docs: clarify policy preview and Station package state#7331
Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughDocumentation updates clarify DGX Station package-manager preparation checks and expand network-policy dry-run preview documentation. ChangesDGX Station preparation
Network policy preview
Estimated code review effort: 1 (Trivial) | ~5 minutes Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
🌿 Preview your docs: https://nvidia-preview-pr-7331.docs.buildwithfern.com/nemoclaw |
PR Review Advisor — InformationalAdvisor assessment: Informational / high confidence Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: None 2 optional E2E recommendations
This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
senthilr-nv
left a comment
There was a problem hiding this comment.
Reviewed against the merged PackageKit, package-state, and policy-scope implementations. The documentation accurately describes the fail-closed boundaries and exact preset-YAML preview behavior. No blocking findings.
<!-- markdownlint-disable MD041 --> ## Summary The OpenClaw, Hermes, and Deep Agents Quickstarts now keep separate source pages with consistent first-run platform ownership. Each Quickstart retains immediate Docker, Windows, DGX Station, Express, and model choices while linking durable details to their canonical owners. The refactor preserves published Quickstart routes, navigation, supported workflows, and Commands and Troubleshooting content. ## Changes - Condense duplicated Docker and platform prose in all three Quickstarts into concise first-run summaries and canonical links. - Keep Docker installation behavior in Prerequisites, Windows preparation in its focused setup page, Station qualification and preparation in the Station page, managed model and headless workflows in Set Up vLLM, and validation status in Platform Support. - Preserve Hermes-specific remote dashboard and API setup, including `CHAT_UI_URL`, port forwarding, and API bearer-token retrieval. - Make each Quickstart installer command set the sandbox name used by its subsequent status, dashboard, and connect commands. - Preserve the complete headless Station workflow and render the correct OpenClaw, Hermes, and Deep Agents selection. - Keep existing routes, navigation entries, and redirects unchanged while generating agent-variant content from the canonical source pages. - Incorporate merged PR #7331, including its PackageKit boundary, without duplicating its integration-policy change. - Incorporate merged PR #7327 while keeping Platform Support as the canonical Station validation-status owner. - Incorporate merged PR #7285 while keeping its existing-vLLM ownership handoff in the canonical Station preparation page. ## Product Scope Verdict: In scope. The diff reorganizes existing Quickstart, Station, and vLLM documentation and updates its ownership test. It does not add an integration, solution recipe, custom image, third-party stack, or supported product surface. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [x] Doc only (includes code sample changes) ## Quality Gates - [x] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## DGX Station Hardware Evidence <!-- Required only when scripts/prepare-dgx-station-host.sh changes. Maintainers must review the linked evidence before approving or merging. This is human-reviewed evidence, not authenticated hardware provenance. Exceptional bypasses use existing repository governance and must be documented on the PR. --> - [ ] Tested on DGX Station - Tested commit: Not applicable; `scripts/prepare-dgx-station-host.sh` is unchanged in the PR diff. - Station profile/scenario: Documentation ownership refactor only. - Result: Not applicable. - Supporting evidence: Not applicable. ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable — canonical-base diff-aware hook stages passed against `upstream/main`. - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/station-doc-ownership.test.ts test/check-docs-published-routes.test.ts test/check-docs-links.test.ts` (3 files, 44 tests passed). - [ ] Applicable broad gate passed — Not applicable; this is a focused documentation ownership refactor with targeted tests and the full docs build. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — passed with 0 errors and 2 Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) — Not applicable; no pages were added. Additional validation: - `npm run docs:sync-agent-variants` - `npm run docs` - `npm run source-shape:check` - `git diff --check upstream/main...HEAD` - Generated OpenClaw, Hermes, and Deep Agents Set Up vLLM variants contain the expected agent selection and no residual `<AgentOnly>` directives. - Repository-required documentation writer agent review found no content loss, inaccurate claim, route or anchor drift, or agent-variant regression. This was not a human review. - Automated nine-category security review found no security issue in the documentation and ownership-test diff. This was not a sensitive-path or human security review. Adjacent pre-existing debt, intentionally outside this refactor: - The standalone Station override command and the generic installer command printed by Windows preparation omit `NEMOCLAW_AGENT`, so users following those commands directly must return to the agent-specific Quickstart to preserve Hermes or Deep Agents selection. --- Signed-off-by: Miyoung Choi <miyoungc@nvidia.com> Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com> --------- Signed-off-by: Miyoung Choi <miyoungc@nvidia.com> Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com> Co-authored-by: Senthil Ravichandran <senthilr@nvidia.com> Co-authored-by: Carlos Villela <cvillela@nvidia.com>
<!-- markdownlint-disable MD041 --> ## Summary This change documents the approved DGX Station OTA metadata fallback in the canonical Station preparation guide. It states the public hardware boundary as recognized GB300 hardware while keeping exact PCI identifiers and the accepted-variant count as implementation details. ## Changes - [#7223](#7223) -> `docs/get-started/dgx-station-preparation.mdx`: Document that qualification uses the latest reviewed `DGX_OTA_VERSION`; `DGX_OTA_PRETTY_NAME` must equal `DGX OS` when present; and marker-less OTA hosts require `DGX_PRETTY_NAME=NVIDIA DGX GB300WS`. - Preserve the safe, root-owned release-file gate and `DGX_PLATFORM=DGX Server for GALAXY-GB300` requirement. - Describe the public PCI qualification boundary only as recognized GB300 hardware, without publishing identifiers or an accepted-variant count. - Extend `test/station-doc-ownership.test.ts` to protect canonical ownership, the fallback wording, the public hardware term, and identifier exclusion. - Leave Quickstart, Platform Support, and provider-selection summaries unchanged because their canonical links and summary-level statements remain accurate. - Rebase on merged PackageKit documentation PR #7331. The unpublished Quickstart deduplication work touches the ownership test nearby, so whichever branch lands second may need a mechanical rebase without a semantic wording dependency. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [x] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [x] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: At PR SHA `8cf7b91`, the focused integration test passed 1 file and 4 tests. `npm run docs` passed with the route checker OK, 0 errors, and 2 existing Fern warnings. `npm run check:diff` passed. The exact-head review found no documentation issues: the OTA marker and fallback wording matches the implementation, the force override is limited to recognized GB300 hardware, and the ownership test excludes raw device IDs. - Agent: Codex Desktop <!-- docs-review-head-sha: 8cf7b91 --> <!-- docs-review-agents-blob-sha: 9c9b36d --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable. - Station profile/scenario: Documentation-only clarification of merged behavior. - Result: No host behavior changed. - Supporting evidence: Merged PR #7223 and the current Station classifier and hardware-detection tests. ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/station-doc-ownership.test.ts test/changelog-docs.test.ts`: 2 files and 10 tests passed. - [ ] Applicable broad gate passed — Not run; focused documentation tests and the docs build cover this change. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — The build passed with 0 errors. Fern reported the existing light-mode accent contrast warning. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- Signed-off-by: Miyoung Choi <miyoungc@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Refined DGX Station qualification guidance for GB300 systems, including how OTA hosts qualify using the latest OTA version and accepted version ranges. * Clarified `DGX_OTA_PRETTY_NAME` expectations (including when it may be omitted after OTA upgrades) and strengthened `DGX_PRETTY_NAME` requirements when `DGX_OTA_PRETTY_NAME` is absent. * Tightened the warning for `--force-station-install` to specify it should only be used when automatic Station detection rejects recognized GB300 `/etc/dgx-release` metadata. * **Tests** * Enhanced documentation ownership checks to validate OTA/GB300-specific text and key qualification requirements. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Prekshi Vyas <prekshiv@nvidia.com> Co-authored-by: Carlos Villela <cvillela@nvidia.com> Co-authored-by: Prekshi Vyas <34834085+prekshivyas@users.noreply.github.com>
Summary
This PR documents the full YAML-derived
policy-add --dry-rundisclosure near the preset preview workflow.It also defines the generic Ubuntu package-state boundary for DGX Station preparation.
This post-release documentation follow-up does not change a dated changelog entry.
Changes
docs/network-policy/integration-policy-examples.mdx: Explain that the preview uses the exact preset YAML and discloses endpoint, HTTP rule, and binary scope.docs/get-started/dgx-station-preparation.mdx: Document that NemoClaw accepts and quiesces an idle PackageKit daemon.docs/get-started/dgx-station-preparation.mdx: Document the fail-closed package transaction, lock, package-state, and query boundary before mutation.Type of Change
Quality Gates
DGX Station Hardware Evidence
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run check:diffpassed when hooks were skipped or unavailablenpx vitest run test/changelog-docs.test.ts test/station-doc-ownership.test.ts test/policy-roundtrip-docs.test.ts: 3 files and 12 tests passed.npm run docsbuilds without warnings (doc changes only) — The build passed with 0 errors. Fern reported the existing light-mode accent contrast warning.Signed-off-by: Miyoung Choi miyoungc@nvidia.com
Summary by CodeRabbit