Skip to content

Route computer and playwright calls directly to the VM - #170

Merged
tnsardesai merged 3 commits into
mainfrom
hypeship/tier1-direct-allowlist
Aug 21, 2026
Merged

Route computer and playwright calls directly to the VM#170
tnsardesai merged 3 commits into
mainfrom
hypeship/tier1-direct-allowlist

Conversation

@tnsardesai

@tnsardesaitnsardesai commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Default direct-to-VM routing now includes computer and playwright in addition to curl and telemetry/stream.

computer/screenshot and playwright/execute rewrite to {base_url}/... with the session JWT and drop Authorization. process/*, fs/*, and telemetry/events stay on the API origin.

KERNEL_BROWSER_ROUTING_SUBRESOURCES still overrides the default list. An empty value still disables routing.

Metro-api activity recording for /browser/kernel/* has been merged in kernel/kernel#3417. That was the hard gate for this allowlist flip. The kill switch is leaving base_url unset or setting KERNEL_BROWSER_ROUTING_SUBRESOURCES to empty.

Latency (eu-west)

Comparison script: https://gist.github.com/tnsardesai/6704dfc86e2c0785e03beaf274aa672d

Same eu-west session. Published @onkernel/sdk@0.93.0 still hits api.onkernel.com; this branch rewrites to metro-api.

creating eu-west browser…
session rao32cls5rhduxg9n1a732i5
region eu-west
base_url https://proxy.dub-unruffled-kowalevski.onkernel.com:8443/browser/kernel
cdp host proxy.dub-unruffled-kowalevski.onkernel.com:8443
rounds warmup=2 timed=8
control plane (@onkernel/sdk@0.93.0)
control-plane screenshot 498ms api.onkernel.com
control-plane screenshot 884ms api.onkernel.com
control-plane screenshot 647ms api.onkernel.com
control-plane screenshot 508ms api.onkernel.com
control-plane screenshot 614ms api.onkernel.com
control-plane screenshot 512ms api.onkernel.com
control-plane screenshot 509ms api.onkernel.com
control-plane screenshot 408ms api.onkernel.com
control-plane screenshot 622ms api.onkernel.com
control-plane screenshot 590ms api.onkernel.com
min 410ms p50 513ms p95 650ms max 650ms
direct to VM (kernel-node-sdk#hypeship/tier1-direct-allowlist)
direct-to-vm screenshot 648ms proxy.dub-unruffled-kowalevski.onkernel.com:8443
direct-to-vm screenshot 623ms proxy.dub-unruffled-kowalevski.onkernel.com:8443
direct-to-vm screenshot 321ms proxy.dub-unruffled-kowalevski.onkernel.com:8443
direct-to-vm screenshot 335ms proxy.dub-unruffled-kowalevski.onkernel.com:8443
direct-to-vm screenshot 332ms proxy.dub-unruffled-kowalevski.onkernel.com:8443
direct-to-vm screenshot 329ms proxy.dub-unruffled-kowalevski.onkernel.com:8443
direct-to-vm screenshot 345ms proxy.dub-unruffled-kowalevski.onkernel.com:8443
direct-to-vm screenshot 344ms proxy.dub-unruffled-kowalevski.onkernel.com:8443
direct-to-vm screenshot 339ms proxy.dub-unruffled-kowalevski.onkernel.com:8443
direct-to-vm screenshot 341ms proxy.dub-unruffled-kowalevski.onkernel.com:8443
min 324ms p50 337ms p95 347ms max 347ms
p50 delta control-plane 513ms vs direct 337ms (-176ms)

Test plan

  • default allowlist includes curl, telemetry/stream, computer, playwright
  • computer screenshot and playwright execute rewrite to the VM and drop Authorization
  • process, fs, and telemetry/events stay on the API origin

Note

Medium Risk
Changes default request routing for computer and Playwright APIs (auth header dropped, JWT on VM URL). Env kill switch remains; process/fs/events stay on the control plane.

Overview
Default direct-to-VM routing now includes computer and playwright alongside curl and telemetry/stream. Screenshot and Playwright execute calls rewrite to the session base_url with a JWT query param and drop Authorization.

process, fs, and telemetry/events still go to the control plane. KERNEL_BROWSER_ROUTING_SUBRESOURCES still overrides the list (empty disables routing).

Reviewed by Cursor Bugbot for commit 386880d. Bugbot is set up for automated code reviews on this repo. Configure here.

Add computer and playwright to the default browser routing allowlist
so screenshot and execute traffic can skip the control plane once
metro-api records activity on the kernel proxy.
The asserted list can grow; the test name should not.
@tnsardesai
tnsardesai marked this pull request as ready for review August 20, 2026 23:06

@rgarciargarcia left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

QA’d commit 8439fe5 from a developer’s perspective.

  • Full Jest suite: 408 passed.
  • Focused routing experiments covered all 12 computer/* methods, playwright/execute, request bodies, headers, VM errors, cache eviction, pool acquisition, env overrides, and control-plane fallback.
  • Direct requests use {base_url}, inject the session JWT, and remove Authorization.
  • process/*, fs/*, telemetry/events, logs, and replays remain on the API origin.
  • Missing base_url and KERNEL_BROWSER_ROUTING_SUBRESOURCES="" correctly disable direct routing.

Non-blocking: the PR description mentions screenshot/execute, but the computer prefix routes the entire computer/* surface. It would be useful to state that explicitly and add a nested-path test such as computer/clipboard/read.

No blocking findings.

@tnsardesai
tnsardesai merged commit 2af98bf into mainAug 21, 2026
11 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tnsardesai@rgarcia@sjmiller609