Repository navigation
Configure egress access during golden initialization - #2159
Eitan Yarmush (EItanya) wants to merge 3 commits into
Conversation
| // Initial egress policy, copied atomically when an Actor is created from | ||
| // this template, including the golden Actor used for initialization. The | ||
| // policy is named "default" in the Actor's atespace, with its own metadata. | ||
| // Callers may update or delete the copy independently; changing the Actor's | ||
| // template does not update its policy. If absent, no policy is created; | ||
| // an empty block creates a policy with no rules. | ||
| // | ||
| // +k8s:optional | ||
| EgressPolicyTemplate default_egress_policy = 9; |
There was a problem hiding this comment.
I opted to create another message here for simplicity, but we could opt to instead require the whole EgressPolicy object with metadata and require the name to be default etc.
Julian Gutierrez Oschmann (@juli4n) and Tim Hockin (@thockin) for API context
|
Clarify for me - does this mean that every actor created from such a template has the same policy unless subsequently changed? Maybe that should be opt-in? E.g. Does this also mean that a subsequent call to set policy will require a read-modify-write? That may be surprising. |
Yes it would. However, I think that if you are creating from an
Now that I've spelled that out for you, I actually think these should be separate. The field I created here should really be something like Does that make sense?
Yes, and this is a very good point. I think that can mostly be solved with documentation, but it's definitely an interaction worth calling out. This is also a result of not having multiple policy layers, and therefore needing one policy source of truth for an actor. |
Lior Lieberman (LiorLieberman)
left a comment
There was a problem hiding this comment.
I am worried on just "goldenEgressPolicy". There are going to be many usecases that you need to just fetch github repos/s3/gcs for some assets. Not necessrially part of "golden" - how do we get those to work.
maybe its an "init actor" support and a policy for that? A very common use case for that is "I want an actor with no network, but give it all this github repos available in local folders (e.g for RL)
FWIW init actor can be useful for many other things.
If it's not part of the golden then it's already supported. When an actor comes up from golden it will already have its own identity. I specifically narrowed the scope of this PR to just handle the golden identity. Adding policy for pre readyz should already work.
That would be exactly what this would enable. The actor identity would not be allowed to make network calls, only during golden preparation. Mounting other data can/should be done with volumes otherwise.
|
Copy an optional template policy when creating an actor, including the golden actor, and write the actor and policy in one transaction. Preserve the distinction between an absent default and an explicitly empty policy, and let each actor policy evolve independently. Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
Expose golden_egress_policy for network access during golden initialization. Create its policy atomically with the golden actor while leaving ordinary actors, including golden snapshot restores, without an inherited runtime policy. Preserve absent and explicitly empty policies. Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
Reject a configured golden policy with no rules, since it grants no access beyond omitting the policy. Keep the policy object for future fields. Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
f5b31fb to
cc5a23a
Compare
Adds
ActorTemplate.goldenEgressPolicyto configure network access while preparing the golden snapshot. The golden actor and its policy are created in one transaction, so the policy exists before initialization starts.The policy object contains only rules today and leaves room for additional fields. Rules use the existing egress validation and defaults. Omitting the field creates no policy. When set, it must contain at least one rule. Ordinary actors, including those restored from the golden snapshot, start without an egress policy. Callers configure their runtime access separately with
CreateActorEgressPolicy.Related to #1324. Motivation and API rationale: #2358.
-race. All repository verifier scripts pass. Validated after rebasing onto upstream59c5b2a54. Fullmake verifyfails in the known CA-file reload tests in ateapi, atelet, and CSI, previously reproduced on unchanged upstream.