Use the prebuilt k8s-sandbox-router image (#256)

This commit is contained in:
Jaana Dogan
2026-04-27 07:40:25 -07:00
committed by GitHub
parent ff8095fe30
commit 3cce8cf42d
4 changed files with 10 additions and 28 deletions
+4 -5
View File
@@ -61,11 +61,6 @@ deps:
@go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@latest
@echo "Dependencies installed!"
# Build Sandbox Router Static Binary
build-router:
@echo "Building sandbox-router Linux binary..."
@GOOS=linux CGO_ENABLED=0 GOARCH=amd64 go build -o sandbox-router ./cmd/sandbox-router
clean-logs:
@echo "Cleaning the event logs..."
rm -rf ./eventlog
@@ -78,3 +73,7 @@ ax-image:
ate-agent-image:
@echo "Building ATE agent container image with ko..."
GOFLAGS="-tags=ate" ko build --base-import-paths ./internal/examples/ate_agent
k8s-sandbox-router-image:
@echo "Building sandbox-router container image with ko..."
ko build --base-import-paths ./cmd/k8s-sandbox-router
@@ -30,20 +30,6 @@ spec:
spec:
containers:
- name: router
# TODO: consider other options instead of Alpine
image: alpine:latest
command: ["/bin/sh", "-c"]
args:
- |
while [ ! -f /app/.done ]; do sleep 1; done
echo "Starting router..."
chmod +x /app/sandbox-router
exec /app/sandbox-router
image: gcr.io/ax-container-images/k8s-sandbox-router
ports:
- containerPort: 8080
volumeMounts:
- name: app-vol
mountPath: /app
volumes:
- name: app-vol
emptyDir: {}
+5 -8
View File
@@ -10,15 +10,12 @@ AX supports dynamically provisioning secure, isolated agents on Kubernetes via t
## Setup: Deploying the Router
Before using Sandbox Agents remotely and developing locally, you must deploy the `sandbox-router` into your cluster. This router proxies traffic securely to the isolated gVisor pods (direct port-forwarding to gVisor pods is not supported by Kubernetes due to netstack isolation).
1. Cross-compile the proxy binary via Make and inject it into an Alpine Pod:
1. Apply the manifest:
```bash
# Build the router for linux and copy it into the cluster
make build-router
kubectl apply -f cmd/sandbox-router/sandbox-router.yaml
kubectl wait --for=condition=Ready pod -l app=sandbox-router --timeout=60s
POD_NAME=$(kubectl get pods -l app=sandbox-router -o jsonpath='{.items[0].metadata.name}')
kubectl cp sandbox-router $POD_NAME:/app/sandbox-router
kubectl exec $POD_NAME -- touch /app/.done
# Apply the manifest
kubectl apply -f cmd/k8s-sandbox-router/sandbox-router.yaml
kubectl rollout status deployment/sandbox-router --timeout=60s
```
2. Expose it as a service: