Skip to content

Clarify Sandbox2 startup self-check on incapable hosts - #3227

Open
valeriy42 wants to merge 2 commits into
elastic:mainfrom
valeriy42:fix/sandbox2-self-check-warning
Open

valeriy42 wants to merge 2 commits into
elastic:mainfrom
valeriy42:fix/sandbox2-self-check-warning

Conversation

@valeriy42

@valeriy42 valeriy42 commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Log the Sandbox2 environment self-check once per controller, at the first --requireSandbox launch of pytorch_inference, not at controller startup. Nodes with sandbox_enabled false never run the probe or emit the line.
  • Reword the self-check for that context (definitive verdict per confinement level at INFO). Per-launch noConfinementMessage() ERROR refusal is unchanged.
  • Trade-off: host capability is no longer visible in logs until the first sandboxed launch; incapable hosts still fail immediately with the existing explained error returned to Elasticsearch.

Log host capability at INFO with wording that matches the default-off
sandbox_enabled setting; keep launch-time refusal messages unchanged.
@elasticsearchmachine

Copy link
Copy Markdown

Pinging @elastic/ml-core (Team:ML)

Probe and log host capability only when the controller routes a
sandboxed pytorch_inference spawn, so index-tier nodes that never opt in
do not emit the line at startup.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants