Skip to content

container: surface target bootstrap failure before sidecar namespace error #81

Description

@sixtoad

Defect

When a Leash-managed target exits during its bootstrap entrypoint, the runner immediately launches the sidecar. Docker then rejects the sidecar with cannot join network namespace of a non running container, and that secondary error is the only diagnostic surfaced to the orchestrator.

The primary target diagnostic remains only in docker logs <target> and is removed during normal cleanup.

Reproduction

  • Walk v0.2.2 (3b2431d)
  • Leash CLI release tag native-v0.3.2 (43e8715), using its Docker/container backend
  • Target image walk33-bmad-codex:v0.2.2
  • Synthetic credential only

The target bootstrap exits with:

leash-error: update-ca-trust or update-ca-certificates not found

The caller instead receives:

cannot join network namespace of a non running container

Process tracing confirms the Docker/container runner launched the target first with --user 0 --entrypoint /leash/leash-entry-linux-amd64; this is independent of target Config.User handling and did not exercise Leash's host-process native runtime.

Expected

  • Detect target exit before or while launching the sidecar.
  • Surface the target bootstrap exit code and sanitized target diagnostic as the primary error.
  • Keep the sidecar namespace error, if useful, as secondary context only.
  • Preserve machine-output stdout purity and do not expose environment values, credential contents, or secrets.
  • Cover an intentionally failing target bootstrap in a focused runner regression.

Relationship

Discovered while correcting Walk #64. Walk owns the incompatible generated image in Walk PR #66; Leash owns preservation of the primary bootstrap diagnostic.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions