Repository navigation
Actors can reach the network while they boot, before their wakeup probe passes - #2117
Quentin Bisson (QuentinBisson) wants to merge 1 commit into
Conversation
f788639 to
8151b8d
Compare
8151b8d to
de5bd12
Compare
|
Quentin Bisson (@QuentinBisson) I think this doesn't do anything without #2159 allowing for policies to be applied to goldens |
|
You're totally right. I forgot to link it here. I did not want to make the other PR bigger |
de5bd12 to
d689539
Compare
|
To clarify my earlier reply: the two PRs are complementary. #2159 gives the golden actor a policy, and this PR turns egress on before readyz, so the golden's boot fetch needs both. This one also helps any actor that already has a policy and fetches while booting or restoring. I've linked #2159 in the description. |
An actor's egress was turned on only after every container answered its wakeup probe, and the egress gateway admitted RUNNING actors only. A workload that downloads what it needs to become ready therefore could not start, and its template never got a golden snapshot. Egress is now turned on before the first container starts, on both sandbox classes and for both run and restore. Ingress still waits for the probe. The gateway also admits RESUMING actors: RESUMING is saved together with the worker assignment, and every other state has left its worker or is leaving it. atunnel and the gateway log the connections they refuse. Co-authored-by: Timo Derstappen <timo@giantswarm.io> Signed-off-by: QuentinBisson <quentin@giantswarm.io>
d689539 to
a45ab26
Compare
Allow substrate egress for `RESUMING` actors as well as `RUNNING` actors, so workloads can fetch what they need while booting or restoring, before the wakeup probe passes. This supports agent-substrate/substrate#2117. The actor's egress policy still applies. All 91 Substrate integration tests pass with `cargo test -p agentgateway --test integration tests::substrate::`, including coverage for resuming actors, rejected states, and policy enforcement. Formatting checks pass. AI assistance was used for the implementation, tests, and this description. - [ ] As required by the [Code of Conduct](https://github.com/agentgateway/agentgateway/blob/main/CODE_OF_CONDUCT.md#generative-ai-policy), the description, docs, and comments (words meant for humans) are written by a human, not by an LLM. Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
|
Quentin Bisson (@QuentinBisson) this release will have the fix for agw so you don't need conditional logic: https://github.com/agentgateway/agentgateway/actions/runs/37940656707 |
|
Thanks Eitan Yarmush (@EItanya) I'll take a look on monday |
sounds good, btw I brought this whole issue up in the community meeting and we're doing our best to get it done for GA |
An actor's egress was turned on only after every container answered its wakeup probe, so a workload that downloads what it needs to become ready (a model, a Git repository) could not start. atunnel closed the connection inside the sandbox before it reached the gateway. Egress is now turned on before the first container starts, on both sandbox classes and for both run and restore; ingress still waits for the probe. The atenet gateway admits
RESUMINGactors as well asRUNNINGones, and atunnel and the gateway now log the connections they refuse.The actor's EgressPolicy still applies. A golden actor has none today, so its boot fetch stays refused until #2159 lets the template give the golden actor a policy during golden preparation; the new e2e test gives the golden actor a policy directly. The agentgateway dataplane admits
RUNNINGactors only and needs its own change, so the test skips on that lane.Tested on kind with the envoy dataplane: the test passes with this change and fails without it.
Part of #1543