## NVIDIA/OpenShell — v0.1.2…v0.1.3-pre.1

_37 commits._

### Features
- **Add bearer token authorization passthrough** — Services can now pass through bearer authorization tokens directly to upstream handlers. This includes updates to service routing, SDK support across multiple languages (Go, TypeScript, Python), and comprehensive end-to-end tests for both HTTP and HTTPS service configurations. (912a077)
- **feat(providers): serve sandbox config files on demand (#3832)** (252882f)
- **feat(providers): add OCI Generative AI example provider profile (#3904)** (5c0c9e4)
- **feat(helm): configure gateway OCSF JSONL output (#3876)** (33a8eac)
- **feat(server): write gateway OCSF events to JSONL (#3264)** (a875add)
- **feat(docker): support corporate proxy CA bundles (#3549)** (9cb72ba)
- **feat(sandbox): add main restart policy (#2798)** (acbac9c)
- **feat(mcp): inspect requests with Tower-selected protocol profiles (#3335)** (1358941)
- **feat(cli): detach sandbox sessions with Ctrl-D (#3744)** (36b0386)
- **feat(helm): make cluster-scoped RBAC optional (#3459)** (d009f30)

### Fixes
- **Reduce noise in server logs** — Fixed overly verbose logging by filtering out response logs for health checks and internal polls. Non-critical polled requests now log at debug level instead of info, keeping the server logs cleaner while still showing important errors at warning level. (dde8a9a)
- **Block protocol upgrades on GraphQL** — GraphQL endpoints now refuse protocol upgrade requests before forwarding them, improving security by preventing unexpected protocol switches. This protection is shared across GraphQL, JSON-RPC, and MCP endpoints while keeping WebSocket inspection separate. (374c035)
- **Allow sandbox name before -- in exec** — The `sandbox exec` command now accepts the sandbox name as a positional argument before the `--` separator, in addition to the `--name` flag. For example, you can now write `openshell sandbox exec my-sandbox -- ls -la` instead of requiring `openshell sandbox exec --name my-sandbox -- ls -la`. (07a486d)
- **Reduce telemetry noise from background polling** — Telemetry spans from routine background health checks and polling operations (like GetSandboxConfig and ReportProviderReadiness) are now logged at DEBUG level instead of INFO, preventing them from flooding the default telemetry export and making traces easier to read. This applies to steady-state polling performed by the supervisor and credential refresh worker. (7caff12)
- **Fix/startup provider readiness (#3819)** (b8932d4)
- **fix(policy): validate raw OPA settings and redact startup errors (#3788)** (798500c)
- **fix(mcp): explain revision-scoped policy and rejections (#3850)** (ba16b9f)
- **fix(supervisor): restore canonical stdin after connection loss (#3852)** (0ea0d31)
- **fix(ci): restore repository permission vetters (#3875)** (c0eb3db)
- **fix(network): preserve pipelined requests after chunked inspection (#3861)** (a6eefcf)
- **fix(cli): keep policy and provider diagnostics readable (#3444)** (12ef86c)
- **fix(e2e): stop sandbox leaks from async Drop cleanup (#3750)** (cfcc373)
- **perf(kubernetes): use a TCP readiness probe for the supervisor (#3700)** (2fe5a0e)
- **fix(cli): keep SSH forwards owned by spawned process (#3759)** (e63cfa1)
- **fix(network): refuse protocol upgrades on JSON-RPC and MCP endpoints (#3753)** (45e3308)
- **fix(server): retry transient sandbox CAS conflicts (#3501)** (9f60f55)
- **fix(e2e): reserve distinct corporate proxy fixture ports (#3761)** (6f00d5c)
- **fix(supervisor): keep session retries during startup (#3765)** (7a4da31)

### Tests
- **Add K3s conformance testing** — Added K3s as a new conformance test environment alongside existing Docker and Podman setups. The change includes K3s installer playbooks, Helm chart packaging, and updates to CI workflows to run K3s conformance tests in integration jobs, with v0.5.0 of Agent Sandbox pinned as the compatibility baseline. (21fea95)
- **test(conformance): verify deletion through sandbox list (#3792)** (5acaaba)
- **test(podman): move podman_preflight into driver-podman integration tests (#3783)** (b8ffe52)
- **test(sandbox): bind ephemeral port in accepted loopback stream test (#3872)** (2ad77ad)
- **test(install): support Bash 3.2 mock capture (#3790)** (b77f5dd)
- **test(e2e): run podman suite with tmachine (#3637)** (eef8bec)
- **test(conformance): migrate file transfer scenarios (#3597)** (0c29d8e)
- **test(cli): migrate gateway-free smoke coverage (#3641)** (c63f8ce)

### Docs
- **docs: remove the architecture directory (#3799)** (cf1bbb9)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/NVIDIA/OpenShell?utm_source=github-action)._