mirror of
https://github.com/google/ax.git
synced 2026-10-02 03:14:37 +08:00
Use the prebuilt k8s-sandbox-router image (#256)
This commit is contained in:
@@ -61,11 +61,6 @@ deps:
|
||||
@go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@latest
|
||||
@echo "Dependencies installed!"
|
||||
|
||||
# Build Sandbox Router Static Binary
|
||||
build-router:
|
||||
@echo "Building sandbox-router Linux binary..."
|
||||
@GOOS=linux CGO_ENABLED=0 GOARCH=amd64 go build -o sandbox-router ./cmd/sandbox-router
|
||||
|
||||
clean-logs:
|
||||
@echo "Cleaning the event logs..."
|
||||
rm -rf ./eventlog
|
||||
@@ -78,3 +73,7 @@ ax-image:
|
||||
ate-agent-image:
|
||||
@echo "Building ATE agent container image with ko..."
|
||||
GOFLAGS="-tags=ate" ko build --base-import-paths ./internal/examples/ate_agent
|
||||
|
||||
k8s-sandbox-router-image:
|
||||
@echo "Building sandbox-router container image with ko..."
|
||||
ko build --base-import-paths ./cmd/k8s-sandbox-router
|
||||
|
||||
+1
-15
@@ -30,20 +30,6 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: router
|
||||
# TODO: consider other options instead of Alpine
|
||||
image: alpine:latest
|
||||
command: ["/bin/sh", "-c"]
|
||||
args:
|
||||
- |
|
||||
while [ ! -f /app/.done ]; do sleep 1; done
|
||||
echo "Starting router..."
|
||||
chmod +x /app/sandbox-router
|
||||
exec /app/sandbox-router
|
||||
image: gcr.io/ax-container-images/k8s-sandbox-router
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
volumeMounts:
|
||||
- name: app-vol
|
||||
mountPath: /app
|
||||
volumes:
|
||||
- name: app-vol
|
||||
emptyDir: {}
|
||||
@@ -10,15 +10,12 @@ AX supports dynamically provisioning secure, isolated agents on Kubernetes via t
|
||||
## Setup: Deploying the Router
|
||||
Before using Sandbox Agents remotely and developing locally, you must deploy the `sandbox-router` into your cluster. This router proxies traffic securely to the isolated gVisor pods (direct port-forwarding to gVisor pods is not supported by Kubernetes due to netstack isolation).
|
||||
|
||||
1. Cross-compile the proxy binary via Make and inject it into an Alpine Pod:
|
||||
1. Apply the manifest:
|
||||
```bash
|
||||
# Build the router for linux and copy it into the cluster
|
||||
make build-router
|
||||
kubectl apply -f cmd/sandbox-router/sandbox-router.yaml
|
||||
kubectl wait --for=condition=Ready pod -l app=sandbox-router --timeout=60s
|
||||
POD_NAME=$(kubectl get pods -l app=sandbox-router -o jsonpath='{.items[0].metadata.name}')
|
||||
kubectl cp sandbox-router $POD_NAME:/app/sandbox-router
|
||||
kubectl exec $POD_NAME -- touch /app/.done
|
||||
|
||||
# Apply the manifest
|
||||
kubectl apply -f cmd/k8s-sandbox-router/sandbox-router.yaml
|
||||
kubectl rollout status deployment/sandbox-router --timeout=60s
|
||||
```
|
||||
|
||||
2. Expose it as a service:
|
||||
|
||||
Reference in New Issue
Block a user