Skip to content

Actors can reach the network while they boot, before their wakeup probe passes - #2117

Open
Quentin Bisson (QuentinBisson) wants to merge 1 commit into
agent-substrate:mainfrom
QuentinBisson:fix/actor-egress-during-boot
Open

Quentin Bisson (QuentinBisson) wants to merge 1 commit into
agent-substrate:mainfrom
QuentinBisson:fix/actor-egress-during-boot

Conversation

@QuentinBisson

@QuentinBisson Quentin Bisson (QuentinBisson) commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

An actor's egress was turned on only after every container answered its wakeup probe, so a workload that downloads what it needs to become ready (a model, a Git repository) could not start. atunnel closed the connection inside the sandbox before it reached the gateway. Egress is now turned on before the first container starts, on both sandbox classes and for both run and restore; ingress still waits for the probe. The atenet gateway admits RESUMING actors as well as RUNNING ones, and atunnel and the gateway now log the connections they refuse.

The actor's EgressPolicy still applies. A golden actor has none today, so its boot fetch stays refused until #2159 lets the template give the golden actor a policy during golden preparation; the new e2e test gives the golden actor a policy directly. The agentgateway dataplane admits RUNNING actors only and needs its own change, so the test skips on that lane.

Tested on kind with the envoy dataplane: the test passes with this change and fails without it.

Part of #1543

  • Tests pass
  • Appropriate changes to documentation are included in the PR

@QuentinBisson
Quentin Bisson (QuentinBisson) force-pushed the fix/actor-egress-during-boot branch 2 times, most recently from f788639 to 8151b8d Compare October 2, 2026 13:08
@QuentinBisson
Quentin Bisson (QuentinBisson) marked this pull request as ready for review October 2, 2026 13:12
@mayawang Maya Wang (mayawang) added the kind/bug Something isn't working / bugfixes label Oct 2, 2026
@mayawang Maya Wang (mayawang) added area/network area/security Security related issue/pr labels Oct 2, 2026
@EItanya

Copy link
Copy Markdown
Collaborator

Quentin Bisson (@QuentinBisson) I think this doesn't do anything without #2159 allowing for policies to be applied to goldens

@QuentinBisson

Copy link
Copy Markdown
Contributor Author

You're totally right. I forgot to link it here. I did not want to make the other PR bigger

@QuentinBisson

Quentin Bisson (QuentinBisson) commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor Author

To clarify my earlier reply: the two PRs are complementary. #2159 gives the golden actor a policy, and this PR turns egress on before readyz, so the golden's boot fetch needs both. This one also helps any actor that already has a policy and fetches while booting or restoring. I've linked #2159 in the description.

An actor's egress was turned on only after every container answered its
wakeup probe, and the egress gateway admitted RUNNING actors only. A
workload that downloads what it needs to become ready therefore could
not start, and its template never got a golden snapshot.

Egress is now turned on before the first container starts, on both
sandbox classes and for both run and restore. Ingress still waits for
the probe. The gateway also admits RESUMING actors: RESUMING is saved
together with the worker assignment, and every other state has left its
worker or is leaving it. atunnel and the gateway log the connections
they refuse.

Co-authored-by: Timo Derstappen <timo@giantswarm.io>
Signed-off-by: QuentinBisson <quentin@giantswarm.io>
Eitan Yarmush (EItanya) added a commit to agentgateway/agentgateway that referenced this pull request Oct 9, 2026
Allow substrate egress for `RESUMING` actors as well as `RUNNING`
actors, so workloads can fetch what they need while booting or
restoring, before the wakeup probe passes. This supports
agent-substrate/substrate#2117. The actor's
egress policy still applies.

All 91 Substrate integration tests pass with `cargo test -p agentgateway
--test integration tests::substrate::`, including coverage for resuming
actors, rejected states, and policy enforcement. Formatting checks pass.

AI assistance was used for the implementation, tests, and this
description.

- [ ] As required by the [Code of
Conduct](https://github.com/agentgateway/agentgateway/blob/main/CODE_OF_CONDUCT.md#generative-ai-policy),
the description, docs, and comments (words meant for humans) are written
by a human, not by an LLM.

Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
@EItanya

Copy link
Copy Markdown
Collaborator

Quentin Bisson (@QuentinBisson) this release will have the fix for agw so you don't need conditional logic: https://github.com/agentgateway/agentgateway/actions/runs/37940656707

@QuentinBisson

Quentin Bisson (QuentinBisson) commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor Author

Thanks Eitan Yarmush (@EItanya) I'll take a look on monday

@EItanya

Copy link
Copy Markdown
Collaborator

Thanks Eitan Yarmush (Eitan Yarmush (@EItanya)) I'll take a look on monday

sounds good, btw I brought this whole issue up in the community meeting and we're doing our best to get it done for GA

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/network area/security Security related issue/pr kind/bug Something isn't working / bugfixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants