## NVIDIA/OpenShell — v0.1.3-pre.1…v0.1.3-pre.2

_5 commits._

### Fixes
- **Clean up ephemeral sandboxes on finalization** — The gateway now deletes ephemeral sandboxes immediately after the main process exits and its result is finalized, rather than waiting for the supervisor to disconnect. This prevents orphaned sandboxes if the connection drops before cleanup can occur. (2935e97)
- **Require full SHA for test commands** — Updated gator-gate workflow to require the complete 40-character commit SHA when posting /ok to test commands, instead of accepting abbreviated SHAs. The skill documentation now includes instructions to read the current head SHA fresh from GitHub before posting the command. (5a91572)
- **Fix local Kubernetes image registry** — Fixed an issue where locally built Kubernetes images were being rewritten to use the default registry (ghcr.io/nvidia), preventing the k3d cluster from pulling them. The fix explicitly clears the global image registry setting in the Kubernetes test environment so locally built images are used as-is. (9912d21)

### Chore
- **Separate sandbox identity from TLS** — Refactored authentication to use bearer tokens for sandbox identity instead of client certificates, while keeping mTLS for gateway endpoints. This decouples sandbox authentication from TLS, allowing sandboxes and user clients to authenticate differently—supervisor pods now only receive the CA certificate and a bearer token, while user client certificates remain external. (021400b)
- **Remove unreachable sandbox code** — Cleaned up obsolete sandbox initialization code that is no longer used after moving workload execution to a separate capability-free container. Removed filesystem preparation, privilege dropping, user/group resolution, and related command-line subcommands that had no callers in the current architecture. (4784e79)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/NVIDIA/OpenShell?utm_source=github-action)._