api: delete the DebugClear RPC and the Debug service (#1346)

Fixes #999.
This commit is contained in:
Joe Betz
2026-09-01 17:46:05 -04:00
committed by GitHub
parent 880456d2a8
commit 3efac91283
18 changed files with 118 additions and 599 deletions
File diff suppressed because one or more lines are too long
@@ -1484,85 +1484,6 @@ class Control:
_registered_method=True)
class DebugStub:
"""Debug is the RPC interface for administrative and debugging operations
(such as wiping state during development).
"""
def __init__(self, channel):
"""Constructor.
Args:
channel: A grpc.Channel.
"""
self.DebugClear = channel.unary_unary(
'/ateapi.Debug/DebugClear',
request_serializer=ateapi__pb2.DebugClearRequest.SerializeToString,
response_deserializer=ateapi__pb2.DebugClearResponse.FromString,
_registered_method=True)
class DebugServicer:
"""Debug is the RPC interface for administrative and debugging operations
(such as wiping state during development).
"""
def DebugClear(self, request, context):
"""Debugging: drop all data from the ate database.
"""
context.set_code(grpc.StatusCode.UNIMPLEMENTED)
context.set_details('Method not implemented!')
raise NotImplementedError('Method not implemented!')
def add_DebugServicer_to_server(servicer, server):
rpc_method_handlers = {
'DebugClear': grpc.unary_unary_rpc_method_handler(
servicer.DebugClear,
request_deserializer=ateapi__pb2.DebugClearRequest.FromString,
response_serializer=ateapi__pb2.DebugClearResponse.SerializeToString,
),
}
generic_handler = grpc.method_handlers_generic_handler(
'ateapi.Debug', rpc_method_handlers)
server.add_generic_rpc_handlers((generic_handler,))
server.add_registered_method_handlers('ateapi.Debug', rpc_method_handlers)
# This class is part of an EXPERIMENTAL API.
class Debug:
"""Debug is the RPC interface for administrative and debugging operations
(such as wiping state during development).
"""
@staticmethod
def DebugClear(request,
target,
options=(),
channel_credentials=None,
call_credentials=None,
insecure=False,
compression=None,
wait_for_ready=None,
timeout=None,
metadata=None):
return grpc.experimental.unary_unary(
request,
target,
'/ateapi.Debug/DebugClear',
ateapi__pb2.DebugClearRequest.SerializeToString,
ateapi__pb2.DebugClearResponse.FromString,
options,
channel_credentials,
insecure,
call_credentials,
compression,
wait_for_ready,
timeout,
metadata,
_registered_method=True)
class ActorIdentityStub:
"""ActorIdentity allows substrate workloads to exchange their
infrastructure-level credentials (k8s service account token, etc.) for a
@@ -171,8 +171,3 @@ func newServiceImpl(
func (s *ServiceImpl) AcquireLease(ctx context.Context, key string) (*store.Lease, error) {
return s.store.AcquireLease(ctx, key)
}
// Pass-through.
func (s *ServiceImpl) DebugClearAll(ctx context.Context) error {
return s.store.DebugClearAll(ctx)
}
@@ -1,39 +0,0 @@
// Copyright 2026 Google LLC
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package debugapi
import (
"context"
"fmt"
"github.com/agent-substrate/substrate/pkg/proto/ateapipb"
"google.golang.org/grpc/codes"
"google.golang.org/grpc/status"
"k8s.io/apimachinery/pkg/util/validation/field"
)
func (s *Service) DebugClear(ctx context.Context, req *ateapipb.DebugClearRequest) (*ateapipb.DebugClearResponse, error) {
if errs := validateDebugClearRequest(req); len(errs) > 0 {
return nil, status.Error(codes.InvalidArgument, errs.ToAggregate().Error())
}
if err := s.persistence.DebugClearAll(ctx); err != nil {
return nil, fmt.Errorf("while running DebugClearAll: %w", err)
}
return &ateapipb.DebugClearResponse{}, nil
}
func validateDebugClearRequest(req *ateapipb.DebugClearRequest) field.ErrorList {
return nil
}
-42
View File
@@ -1,42 +0,0 @@
// Copyright 2026 Google LLC
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package debugapi
import (
"context"
"github.com/agent-substrate/substrate/pkg/proto/ateapipb"
)
// Service implements ateapipb.DebugServer.
type Service struct {
ateapipb.UnimplementedDebugServer
persistence debuggingStore
}
var _ ateapipb.DebugServer = (*Service)(nil)
// NewService creates a new debug service.
func NewService(persistence debuggingStore) *Service {
return &Service{
persistence: persistence,
}
}
// debuggingStore enumerates the exact storage methods needed by
// the debug API and nothing more.
type debuggingStore interface {
DebugClearAll(ctx context.Context) error
}
-9
View File
@@ -1628,12 +1628,3 @@ func (p *Persistence) releaseLease(ctx context.Context, key, token string) error
}
return nil
}
// --- Debug ---
func (p *Persistence) DebugClearAll(ctx context.Context) error {
if _, err := p.pool.Exec(ctx, `TRUNCATE atespaces, actors, actor_egress_policies, actor_templates, actor_snapshots, actor_snapshot_tags, workers, leases, worker_outbox, worker_outbox_trim`); err != nil {
return fmt.Errorf("truncating tables: %w", err)
}
return nil
}
+12 -4
View File
@@ -35,7 +35,7 @@ import (
)
// One Postgres container serves every test in this package; each test gets
// isolation via DebugClearAll rather than a fresh container, which would be
// isolation via clearAll rather than a fresh container, which would be
// far slower. Tests in this package are not safe to run with -parallel.
var (
containerOnce sync.Once
@@ -114,6 +114,16 @@ func requirePool(t *testing.T) *pgxpool.Pool {
return containerPool
}
// clearAll truncates every table so the next test starts from an empty store
// without paying for a fresh database. Nothing in production mass-deletes
// state, so the statement lives here rather than on Persistence.
func clearAll(t *testing.T, p *Persistence) {
t.Helper()
if _, err := p.pool.Exec(context.Background(), `TRUNCATE atespaces, actors, actor_egress_policies, actor_templates, actor_snapshots, actor_snapshot_tags, workers, leases, worker_outbox, worker_outbox_trim`); err != nil {
t.Fatalf("truncating tables: %v", err)
}
}
func setupPostgresPersistence(t *testing.T) *Persistence {
t.Helper()
ctx := context.Background()
@@ -122,9 +132,7 @@ func setupPostgresPersistence(t *testing.T) *Persistence {
t.Fatalf("NewPersistence failed: %v", err)
}
t.Cleanup(p.Close)
if err := p.DebugClearAll(ctx); err != nil {
t.Fatalf("DebugClearAll failed: %v", err)
}
clearAll(t, p)
return p
}
@@ -59,9 +59,7 @@ func TestConnect_DedicatedWatchPool(t *testing.T) {
t.Fatalf("watch pool MaxConns = %d, want %d", got, watchPoolMaxConns)
}
if err := p.DebugClearAll(ctx); err != nil {
t.Fatalf("DebugClearAll failed: %v", err)
}
clearAll(t, p)
watch, err := p.WatchWorkers(ctx)
if err != nil {
t.Fatalf("WatchWorkers failed: %v", err)
-3
View File
@@ -238,9 +238,6 @@ type Interface interface {
// held and renewed automatically until the returned Lease is closed.
// Returns ErrLeaseConflict if the lease is already held by another client.
AcquireLease(ctx context.Context, key string) (*Lease, error)
// DebugClearAll drop all data from the database. Useful for debugging / local testing/
DebugClearAll(ctx context.Context) error
}
// Precondition guards an update with the uid and version the caller observed:
@@ -159,7 +159,6 @@ func RunContractTests(t *testing.T, setup func(t *testing.T) store.Interface) {
runActorSnapshotContractTests(t, setup)
runLeaseContractTests(t, setup)
runListOptionsContractTests(t, setup)
runDebugContractTests(t, setup)
}
func runEgressPolicyContractTests(t *testing.T, setup func(t *testing.T) store.Interface) {
@@ -1976,52 +1975,3 @@ func runLeaseContractTests(t *testing.T, setup func(t *testing.T) store.Interfac
lease.Close()
})
}
// runDebugContractTests covers store-wide debug operations, which span every
// resource kind rather than belonging to any single one.
func runDebugContractTests(t *testing.T, setup func(t *testing.T) store.Interface) {
t.Helper()
t.Run("DebugClearAll", func(t *testing.T) {
s := setup(t)
ctx := context.Background()
if _, err := s.CreateAtespace(ctx, newTestAtespace("team-a")); err != nil {
t.Fatalf("CreateAtespace failed: %v", err)
}
if _, err := s.CreateActor(ctx, &ateapipb.Actor{
Metadata: &ateapipb.ResourceMetadata{Name: "id1", Atespace: "team-a"},
Status: &ateapipb.ActorStatus{State: ateapipb.ActorState_ACTOR_STATE_SUSPENDED},
}); err != nil {
t.Fatalf("CreateActor failed: %v", err)
}
if _, err := s.CreateWorker(ctx, &ateapipb.Worker{WorkerNamespace: "ns", WorkerPool: "pool", WorkerPod: "pod"}); err != nil {
t.Fatalf("CreateWorker failed: %v", err)
}
lease, err := s.AcquireLease(ctx, "lease-1")
if err != nil {
t.Fatalf("AcquireLease failed: %v", err)
}
defer lease.Close()
if err := s.DebugClearAll(ctx); err != nil {
t.Fatalf("DebugClearAll failed: %v", err)
}
if _, err := s.GetAtespace(ctx, "team-a"); !errors.Is(err, store.ErrNotFound) {
t.Errorf("atespace survived DebugClearAll: %v", err)
}
if actors, err := s.ListActors(ctx, "", store.ListOptions{PageSize: 1000}); err != nil || len(actors.Items) != 0 {
t.Errorf("actors survived DebugClearAll: actors=%v err=%v", actors.Items, err)
}
if workers, err := s.ListWorkers(ctx, store.ListOptions{PageSize: 1000}); err != nil || len(workers.Items) != 0 {
t.Errorf("workers survived DebugClearAll: workers=%v err=%v", workers.Items, err)
}
reacquired, err := s.AcquireLease(ctx, "lease-1")
if err != nil {
t.Errorf("lease survived DebugClearAll: %v", err)
} else {
reacquired.Close()
}
})
}
-3
View File
@@ -28,7 +28,6 @@ import (
"github.com/agent-substrate/substrate/cmd/ateapi/internal/actoridentity"
"github.com/agent-substrate/substrate/cmd/ateapi/internal/controlapi"
"github.com/agent-substrate/substrate/cmd/ateapi/internal/debugapi"
"github.com/agent-substrate/substrate/cmd/ateapi/internal/oidcjwt"
"github.com/agent-substrate/substrate/cmd/ateapi/internal/store"
"github.com/agent-substrate/substrate/cmd/ateapi/internal/store/atepg"
@@ -198,7 +197,6 @@ func main() {
}
actorIdentitySrv := actoridentity.New(actorIdentityJWTIssuer, *actorIDJWTPoolFile, actorIDCAPool, persistence, workerCache)
debugSrv := debugapi.NewService(persistence)
lisCfg := &net.ListenConfig{}
lis, err := lisCfg.Listen(ctx, "tcp", *listenAddr)
@@ -233,7 +231,6 @@ func main() {
reflection.Register(mux)
ateapipb.RegisterControlServer(mux, controlSrv)
ateapipb.RegisterActorIdentityServer(mux, actorIdentitySrv)
ateapipb.RegisterDebugServer(mux, debugSrv)
readiness := &serverboot.Readiness{}
go serverboot.StartMetricsServer(ctx, serverboot.MetricsServerOptions{
+1 -4
View File
@@ -251,7 +251,7 @@ kubectl ate logs actors my-actor -a <atespace> -c my-container
Logs are streamable only while the actor is bound to a worker (i.e., `ACTOR_STATE_RUNNING`). For history across worker migrations, route through a centralized log backend (Cloud Logging, Loki, etc.); see `docs/observability.md`.
### Administration & Setup
Commands for bootstrapping the Substrate control plane and debugging local environments.
Commands for bootstrapping the Substrate control plane.
```bash
# Generate a new Actor ID CA pool and push it directly to a Kubernetes Secret
@@ -265,7 +265,4 @@ kubectl ate admin make-jwt-pool \
--name actor-id-jwt-pool \
--secret-namespace ate-system \
--key-id "1"
# DANGEROUS: Completely clear all Actor and Worker tracking state
kubectl ate admin debug-clear-store
```
@@ -1,45 +0,0 @@
// Copyright 2026 Google LLC
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package cmd
import (
"fmt"
"github.com/agent-substrate/substrate/internal/ateclient"
"github.com/agent-substrate/substrate/pkg/proto/ateapipb"
"github.com/spf13/cobra"
)
var debugClearStoreCmd = &cobra.Command{
Use: "debug-clear-store",
Short: "DANGEROUS: Clear all control-plane state",
RunE: func(cmd *cobra.Command, args []string) error {
ctx := cmd.Context()
apiClient, err := ateclient.NewClient(ctx, kubeconfig, k8sContext, endpoint, tokenFile, traceEnabled)
if err != nil {
return fmt.Errorf("failed to connect to ate-api-server: %w", err)
}
defer apiClient.Close()
if _, err := apiClient.DebugClear(ctx, &ateapipb.DebugClearRequest{}); err != nil {
return fmt.Errorf("failed to clear control-plane state: %w", err)
}
fmt.Println("Successfully cleared all control-plane state.")
return nil
},
}
func init() {
adminCmd.AddCommand(debugClearStoreCmd)
}
+3 -1
View File
@@ -26,7 +26,9 @@ are needed for OIDC discovery against some private Kubernetes API servers.
`actorIdentityJWTProvider` identifies the provider allowed to call
`ActorIdentity.MintJWT`. Other authenticated providers can call every RPC.
Authorization and RBAC are not implemented yet, so only configure providers
whose users should have full access, including `DebugClear`.
whose users should have full control of the entire control plane: every
atespace, actor, actor template, egress policy, snapshot and worker in the
cluster.
## Google Cloud CLI tokens
+1 -4
View File
@@ -53,10 +53,9 @@ const (
liveBundleSelector = "podcert.ate.dev/canarying=live"
)
// Client wraps the gRPC ControlClient and DebugClient and ensures the port-forward connection is closed when done.
// Client wraps the gRPC ControlClient and ensures the port-forward connection is closed when done.
type Client struct {
ateapipb.ControlClient
ateapipb.DebugClient
conn *grpc.ClientConn
cancel func()
tracerProvider *sdktrace.TracerProvider
@@ -142,7 +141,6 @@ func dialDirect(ctx context.Context, kubeconfigPath, k8sContext, endpoint, token
}
return &Client{
ControlClient: ateapipb.NewControlClient(conn),
DebugClient: ateapipb.NewDebugClient(conn),
conn: conn,
cancel: func() {},
}, nil
@@ -203,7 +201,6 @@ func dialPortForward(ctx context.Context, kubeconfigPath, k8sContext, tokenFile
return &Client{
ControlClient: ateapipb.NewControlClient(conn),
DebugClient: ateapipb.NewDebugClient(conn),
conn: conn,
cancel: stopForward,
}, nil
+71 -152
View File
@@ -6261,78 +6261,6 @@ func (x *ActorAssignment) GetActorTemplateRef() *ObjectRef {
return nil
}
type DebugClearRequest struct {
state protoimpl.MessageState `protogen:"open.v1"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *DebugClearRequest) Reset() {
*x = DebugClearRequest{}
mi := &file_ateapi_proto_msgTypes[88]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *DebugClearRequest) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*DebugClearRequest) ProtoMessage() {}
func (x *DebugClearRequest) ProtoReflect() protoreflect.Message {
mi := &file_ateapi_proto_msgTypes[88]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use DebugClearRequest.ProtoReflect.Descriptor instead.
func (*DebugClearRequest) Descriptor() ([]byte, []int) {
return file_ateapi_proto_rawDescGZIP(), []int{88}
}
type DebugClearResponse struct {
state protoimpl.MessageState `protogen:"open.v1"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
func (x *DebugClearResponse) Reset() {
*x = DebugClearResponse{}
mi := &file_ateapi_proto_msgTypes[89]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
func (x *DebugClearResponse) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*DebugClearResponse) ProtoMessage() {}
func (x *DebugClearResponse) ProtoReflect() protoreflect.Message {
mi := &file_ateapi_proto_msgTypes[89]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use DebugClearResponse.ProtoReflect.Descriptor instead.
func (*DebugClearResponse) Descriptor() ([]byte, []int) {
return file_ateapi_proto_rawDescGZIP(), []int{89}
}
type MintJWTRequest struct {
state protoimpl.MessageState `protogen:"open.v1"`
// The audiences the minted JWT is bound to. Tokens are only issued with
@@ -6358,7 +6286,7 @@ type MintJWTRequest struct {
func (x *MintJWTRequest) Reset() {
*x = MintJWTRequest{}
mi := &file_ateapi_proto_msgTypes[90]
mi := &file_ateapi_proto_msgTypes[88]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -6370,7 +6298,7 @@ func (x *MintJWTRequest) String() string {
func (*MintJWTRequest) ProtoMessage() {}
func (x *MintJWTRequest) ProtoReflect() protoreflect.Message {
mi := &file_ateapi_proto_msgTypes[90]
mi := &file_ateapi_proto_msgTypes[88]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -6383,7 +6311,7 @@ func (x *MintJWTRequest) ProtoReflect() protoreflect.Message {
// Deprecated: Use MintJWTRequest.ProtoReflect.Descriptor instead.
func (*MintJWTRequest) Descriptor() ([]byte, []int) {
return file_ateapi_proto_rawDescGZIP(), []int{90}
return file_ateapi_proto_rawDescGZIP(), []int{88}
}
func (x *MintJWTRequest) GetAudience() []string {
@@ -6442,7 +6370,7 @@ type MintJWTResponse struct {
func (x *MintJWTResponse) Reset() {
*x = MintJWTResponse{}
mi := &file_ateapi_proto_msgTypes[91]
mi := &file_ateapi_proto_msgTypes[89]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -6454,7 +6382,7 @@ func (x *MintJWTResponse) String() string {
func (*MintJWTResponse) ProtoMessage() {}
func (x *MintJWTResponse) ProtoReflect() protoreflect.Message {
mi := &file_ateapi_proto_msgTypes[91]
mi := &file_ateapi_proto_msgTypes[89]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -6467,7 +6395,7 @@ func (x *MintJWTResponse) ProtoReflect() protoreflect.Message {
// Deprecated: Use MintJWTResponse.ProtoReflect.Descriptor instead.
func (*MintJWTResponse) Descriptor() ([]byte, []int) {
return file_ateapi_proto_rawDescGZIP(), []int{91}
return file_ateapi_proto_rawDescGZIP(), []int{89}
}
func (x *MintJWTResponse) GetActorJwt() string {
@@ -6514,7 +6442,7 @@ type MintCertRequest struct {
func (x *MintCertRequest) Reset() {
*x = MintCertRequest{}
mi := &file_ateapi_proto_msgTypes[92]
mi := &file_ateapi_proto_msgTypes[90]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -6526,7 +6454,7 @@ func (x *MintCertRequest) String() string {
func (*MintCertRequest) ProtoMessage() {}
func (x *MintCertRequest) ProtoReflect() protoreflect.Message {
mi := &file_ateapi_proto_msgTypes[92]
mi := &file_ateapi_proto_msgTypes[90]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -6539,7 +6467,7 @@ func (x *MintCertRequest) ProtoReflect() protoreflect.Message {
// Deprecated: Use MintCertRequest.ProtoReflect.Descriptor instead.
func (*MintCertRequest) Descriptor() ([]byte, []int) {
return file_ateapi_proto_rawDescGZIP(), []int{92}
return file_ateapi_proto_rawDescGZIP(), []int{90}
}
func (x *MintCertRequest) GetWorker() *ObjectRef {
@@ -6582,7 +6510,7 @@ type MintCertResponse struct {
func (x *MintCertResponse) Reset() {
*x = MintCertResponse{}
mi := &file_ateapi_proto_msgTypes[93]
mi := &file_ateapi_proto_msgTypes[91]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
@@ -6594,7 +6522,7 @@ func (x *MintCertResponse) String() string {
func (*MintCertResponse) ProtoMessage() {}
func (x *MintCertResponse) ProtoReflect() protoreflect.Message {
mi := &file_ateapi_proto_msgTypes[93]
mi := &file_ateapi_proto_msgTypes[91]
if x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
@@ -6607,7 +6535,7 @@ func (x *MintCertResponse) ProtoReflect() protoreflect.Message {
// Deprecated: Use MintCertResponse.ProtoReflect.Descriptor instead.
func (*MintCertResponse) Descriptor() ([]byte, []int) {
return file_ateapi_proto_rawDescGZIP(), []int{93}
return file_ateapi_proto_rawDescGZIP(), []int{91}
}
func (x *MintCertResponse) GetActorCertificates() [][]byte {
@@ -6948,9 +6876,7 @@ const file_ateapi_proto_rawDesc = "" +
"\x0fActorAssignment\x12'\n" +
"\x05actor\x18\x02 \x01(\v2\x11.ateapi.ObjectRefR\x05actor\x12\x1b\n" +
"\tactor_uid\x18\x03 \x01(\tR\bactorUid\x12?\n" +
"\x12actor_template_ref\x18\x04 \x01(\v2\x11.ateapi.ObjectRefR\x10actorTemplateRef\"\x13\n" +
"\x11DebugClearRequest\"\x14\n" +
"\x12DebugClearResponse\"\x84\x01\n" +
"\x12actor_template_ref\x18\x04 \x01(\v2\x11.ateapi.ObjectRefR\x10actorTemplateRef\"\x84\x01\n" +
"\x0eMintJWTRequest\x12\x1a\n" +
"\baudience\x18\x01 \x03(\tR\baudience\x12\x1a\n" +
"\batespace\x18\x02 \x01(\tR\batespace\x12\x1d\n" +
@@ -7039,10 +6965,7 @@ const file_ateapi_proto_rawDesc = "" +
"\x13CreateActorTemplate\x12\".ateapi.CreateActorTemplateRequest\x1a\x15.ateapi.ActorTemplate\"\x00\x12L\n" +
"\x10GetActorTemplate\x12\x1f.ateapi.GetActorTemplateRequest\x1a\x15.ateapi.ActorTemplate\"\x00\x12]\n" +
"\x12ListActorTemplates\x12!.ateapi.ListActorTemplatesRequest\x1a\".ateapi.ListActorTemplatesResponse\"\x00\x12R\n" +
"\x13DeleteActorTemplate\x12\".ateapi.DeleteActorTemplateRequest\x1a\x15.ateapi.ActorTemplate\"\x002N\n" +
"\x05Debug\x12E\n" +
"\n" +
"DebugClear\x12\x19.ateapi.DebugClearRequest\x1a\x1a.ateapi.DebugClearResponse\"\x002\x8a\x01\n" +
"\x13DeleteActorTemplate\x12\".ateapi.DeleteActorTemplateRequest\x1a\x15.ateapi.ActorTemplate\"\x002\x8a\x01\n" +
"\rActorIdentity\x12:\n" +
"\aMintJWT\x12\x16.ateapi.MintJWTRequest\x1a\x17.ateapi.MintJWTResponse\x12=\n" +
"\bMintCert\x12\x17.ateapi.MintCertRequest\x1a\x18.ateapi.MintCertResponseB9Z7github.com/agent-substrate/substrate/pkg/proto/ateapipbb\x06proto3"
@@ -7060,7 +6983,7 @@ func file_ateapi_proto_rawDescGZIP() []byte {
}
var file_ateapi_proto_enumTypes = make([]protoimpl.EnumInfo, 9)
var file_ateapi_proto_msgTypes = make([]protoimpl.MessageInfo, 97)
var file_ateapi_proto_msgTypes = make([]protoimpl.MessageInfo, 95)
var file_ateapi_proto_goTypes = []any{
(SnapshotContentScope)(0), // 0: ateapi.SnapshotContentScope
(ActorSnapshotTagScope)(0), // 1: ateapi.ActorSnapshotTagScope
@@ -7159,25 +7082,23 @@ var file_ateapi_proto_goTypes = []any{
(*WorkerStatus)(nil), // 94: ateapi.WorkerStatus
(*WorkerCapacity)(nil), // 95: ateapi.WorkerCapacity
(*ActorAssignment)(nil), // 96: ateapi.ActorAssignment
(*DebugClearRequest)(nil), // 97: ateapi.DebugClearRequest
(*DebugClearResponse)(nil), // 98: ateapi.DebugClearResponse
(*MintJWTRequest)(nil), // 99: ateapi.MintJWTRequest
(*MintJWTResponse)(nil), // 100: ateapi.MintJWTResponse
(*MintCertRequest)(nil), // 101: ateapi.MintCertRequest
(*MintCertResponse)(nil), // 102: ateapi.MintCertResponse
nil, // 103: ateapi.Selector.MatchLabelsEntry
nil, // 104: ateapi.ExternalVolume.VolumeContextEntry
nil, // 105: ateapi.Worker.LabelsEntry
(*timestamppb.Timestamp)(nil), // 106: google.protobuf.Timestamp
(*emptypb.Empty)(nil), // 107: google.protobuf.Empty
(*MintJWTRequest)(nil), // 97: ateapi.MintJWTRequest
(*MintJWTResponse)(nil), // 98: ateapi.MintJWTResponse
(*MintCertRequest)(nil), // 99: ateapi.MintCertRequest
(*MintCertResponse)(nil), // 100: ateapi.MintCertResponse
nil, // 101: ateapi.Selector.MatchLabelsEntry
nil, // 102: ateapi.ExternalVolume.VolumeContextEntry
nil, // 103: ateapi.Worker.LabelsEntry
(*timestamppb.Timestamp)(nil), // 104: google.protobuf.Timestamp
(*emptypb.Empty)(nil), // 105: google.protobuf.Empty
}
var file_ateapi_proto_depIdxs = []int32{
0, // 0: ateapi.LocalSnapshotInfo.content_scope:type_name -> ateapi.SnapshotContentScope
103, // 1: ateapi.Selector.match_labels:type_name -> ateapi.Selector.MatchLabelsEntry
106, // 2: ateapi.ResourceMetadata.create_time:type_name -> google.protobuf.Timestamp
106, // 3: ateapi.ResourceMetadata.update_time:type_name -> google.protobuf.Timestamp
101, // 1: ateapi.Selector.match_labels:type_name -> ateapi.Selector.MatchLabelsEntry
104, // 2: ateapi.ResourceMetadata.create_time:type_name -> google.protobuf.Timestamp
104, // 3: ateapi.ResourceMetadata.update_time:type_name -> google.protobuf.Timestamp
8, // 4: ateapi.ExternalVolume.status:type_name -> ateapi.ExternalVolume.Status
104, // 5: ateapi.ExternalVolume.volume_context:type_name -> ateapi.ExternalVolume.VolumeContextEntry
102, // 5: ateapi.ExternalVolume.volume_context:type_name -> ateapi.ExternalVolume.VolumeContextEntry
11, // 6: ateapi.Actor.metadata:type_name -> ateapi.ResourceMetadata
27, // 7: ateapi.Actor.actor_template:type_name -> ateapi.ObjectRef
10, // 8: ateapi.Actor.worker_selector:type_name -> ateapi.Selector
@@ -7187,7 +7108,7 @@ var file_ateapi_proto_depIdxs = []int32{
15, // 12: ateapi.EgressPolicy.rules:type_name -> ateapi.EgressRule
16, // 13: ateapi.EgressRule.hostnames:type_name -> ateapi.HostnameRule
17, // 14: ateapi.EgressRule.ip_blocks:type_name -> ateapi.IPBlockRule
107, // 15: ateapi.EgressRule.all:type_name -> google.protobuf.Empty
105, // 15: ateapi.EgressRule.all:type_name -> google.protobuf.Empty
18, // 16: ateapi.HostnameRule.effects:type_name -> ateapi.EgressRuleEffects
19, // 17: ateapi.EgressRuleEffects.inject_static_headers:type_name -> ateapi.CredentialHeaderInjection
2, // 18: ateapi.ActorStatus.state:type_name -> ateapi.ActorState
@@ -7217,7 +7138,7 @@ var file_ateapi_proto_depIdxs = []int32{
32, // 42: ateapi.ActorTemplate.status:type_name -> ateapi.ActorTemplateStatus
30, // 43: ateapi.Resources.limits:type_name -> ateapi.Limits
27, // 44: ateapi.GoldenSnapshotStatus.golden_snapshot:type_name -> ateapi.ObjectRef
106, // 45: ateapi.GoldenSnapshotStatus.take_golden_snapshot_at:type_name -> google.protobuf.Timestamp
104, // 45: ateapi.GoldenSnapshotStatus.take_golden_snapshot_at:type_name -> google.protobuf.Timestamp
31, // 46: ateapi.ActorTemplateStatus.golden_snapshot_status:type_name -> ateapi.GoldenSnapshotStatus
3, // 47: ateapi.SandboxConfig.sandbox_class:type_name -> ateapi.SandboxClass
0, // 48: ateapi.SnapshotsConfig.on_pause:type_name -> ateapi.SnapshotContentScope
@@ -7279,7 +7200,7 @@ var file_ateapi_proto_depIdxs = []int32{
27, // 104: ateapi.DrainWorkerRequest.worker:type_name -> ateapi.ObjectRef
13, // 105: ateapi.ListActorsResponse.actors:type_name -> ateapi.Actor
11, // 106: ateapi.Worker.metadata:type_name -> ateapi.ResourceMetadata
105, // 107: ateapi.Worker.labels:type_name -> ateapi.Worker.LabelsEntry
103, // 107: ateapi.Worker.labels:type_name -> ateapi.Worker.LabelsEntry
95, // 108: ateapi.Worker.capacity:type_name -> ateapi.WorkerCapacity
94, // 109: ateapi.Worker.status:type_name -> ateapi.WorkerStatus
6, // 110: ateapi.WorkerStatus.state:type_name -> ateapi.WorkerState
@@ -7320,46 +7241,44 @@ var file_ateapi_proto_depIdxs = []int32{
58, // 145: ateapi.Control.GetActorTemplate:input_type -> ateapi.GetActorTemplateRequest
59, // 146: ateapi.Control.ListActorTemplates:input_type -> ateapi.ListActorTemplatesRequest
61, // 147: ateapi.Control.DeleteActorTemplate:input_type -> ateapi.DeleteActorTemplateRequest
97, // 148: ateapi.Debug.DebugClear:input_type -> ateapi.DebugClearRequest
99, // 149: ateapi.ActorIdentity.MintJWT:input_type -> ateapi.MintJWTRequest
101, // 150: ateapi.ActorIdentity.MintCert:input_type -> ateapi.MintCertRequest
13, // 151: ateapi.Control.GetActor:output_type -> ateapi.Actor
13, // 152: ateapi.Control.CreateActor:output_type -> ateapi.Actor
13, // 153: ateapi.Control.UpdateActor:output_type -> ateapi.Actor
66, // 154: ateapi.Control.SuspendActor:output_type -> ateapi.SuspendActorResponse
68, // 155: ateapi.Control.PauseActor:output_type -> ateapi.PauseActorResponse
70, // 156: ateapi.Control.ResumeActor:output_type -> ateapi.ResumeActorResponse
13, // 157: ateapi.Control.DeleteActor:output_type -> ateapi.Actor
14, // 158: ateapi.Control.GetActorEgressPolicy:output_type -> ateapi.EgressPolicy
14, // 159: ateapi.Control.CreateActorEgressPolicy:output_type -> ateapi.EgressPolicy
14, // 160: ateapi.Control.UpdateActorEgressPolicy:output_type -> ateapi.EgressPolicy
14, // 161: ateapi.Control.DeleteActorEgressPolicy:output_type -> ateapi.EgressPolicy
23, // 162: ateapi.Control.GetActorSnapshot:output_type -> ateapi.ActorSnapshot
25, // 163: ateapi.Control.GetActorSnapshotTag:output_type -> ateapi.ActorSnapshotTag
79, // 164: ateapi.Control.ListActorSnapshots:output_type -> ateapi.ListActorSnapshotsResponse
25, // 165: ateapi.Control.CreateActorSnapshotTag:output_type -> ateapi.ActorSnapshotTag
25, // 166: ateapi.Control.UpdateActorSnapshotTag:output_type -> ateapi.ActorSnapshotTag
25, // 167: ateapi.Control.DeleteActorSnapshotTag:output_type -> ateapi.ActorSnapshotTag
85, // 168: ateapi.Control.ListWorkers:output_type -> ateapi.ListWorkersResponse
93, // 169: ateapi.Control.GetWorker:output_type -> ateapi.Worker
93, // 170: ateapi.Control.CreateWorker:output_type -> ateapi.Worker
93, // 171: ateapi.Control.UpdateWorker:output_type -> ateapi.Worker
93, // 172: ateapi.Control.DeleteWorker:output_type -> ateapi.Worker
93, // 173: ateapi.Control.DrainWorker:output_type -> ateapi.Worker
92, // 174: ateapi.Control.ListActors:output_type -> ateapi.ListActorsResponse
26, // 175: ateapi.Control.CreateAtespace:output_type -> ateapi.Atespace
26, // 176: ateapi.Control.GetAtespace:output_type -> ateapi.Atespace
55, // 177: ateapi.Control.ListAtespaces:output_type -> ateapi.ListAtespacesResponse
26, // 178: ateapi.Control.DeleteAtespace:output_type -> ateapi.Atespace
28, // 179: ateapi.Control.CreateActorTemplate:output_type -> ateapi.ActorTemplate
28, // 180: ateapi.Control.GetActorTemplate:output_type -> ateapi.ActorTemplate
60, // 181: ateapi.Control.ListActorTemplates:output_type -> ateapi.ListActorTemplatesResponse
28, // 182: ateapi.Control.DeleteActorTemplate:output_type -> ateapi.ActorTemplate
98, // 183: ateapi.Debug.DebugClear:output_type -> ateapi.DebugClearResponse
100, // 184: ateapi.ActorIdentity.MintJWT:output_type -> ateapi.MintJWTResponse
102, // 185: ateapi.ActorIdentity.MintCert:output_type -> ateapi.MintCertResponse
151, // [151:186] is the sub-list for method output_type
116, // [116:151] is the sub-list for method input_type
97, // 148: ateapi.ActorIdentity.MintJWT:input_type -> ateapi.MintJWTRequest
99, // 149: ateapi.ActorIdentity.MintCert:input_type -> ateapi.MintCertRequest
13, // 150: ateapi.Control.GetActor:output_type -> ateapi.Actor
13, // 151: ateapi.Control.CreateActor:output_type -> ateapi.Actor
13, // 152: ateapi.Control.UpdateActor:output_type -> ateapi.Actor
66, // 153: ateapi.Control.SuspendActor:output_type -> ateapi.SuspendActorResponse
68, // 154: ateapi.Control.PauseActor:output_type -> ateapi.PauseActorResponse
70, // 155: ateapi.Control.ResumeActor:output_type -> ateapi.ResumeActorResponse
13, // 156: ateapi.Control.DeleteActor:output_type -> ateapi.Actor
14, // 157: ateapi.Control.GetActorEgressPolicy:output_type -> ateapi.EgressPolicy
14, // 158: ateapi.Control.CreateActorEgressPolicy:output_type -> ateapi.EgressPolicy
14, // 159: ateapi.Control.UpdateActorEgressPolicy:output_type -> ateapi.EgressPolicy
14, // 160: ateapi.Control.DeleteActorEgressPolicy:output_type -> ateapi.EgressPolicy
23, // 161: ateapi.Control.GetActorSnapshot:output_type -> ateapi.ActorSnapshot
25, // 162: ateapi.Control.GetActorSnapshotTag:output_type -> ateapi.ActorSnapshotTag
79, // 163: ateapi.Control.ListActorSnapshots:output_type -> ateapi.ListActorSnapshotsResponse
25, // 164: ateapi.Control.CreateActorSnapshotTag:output_type -> ateapi.ActorSnapshotTag
25, // 165: ateapi.Control.UpdateActorSnapshotTag:output_type -> ateapi.ActorSnapshotTag
25, // 166: ateapi.Control.DeleteActorSnapshotTag:output_type -> ateapi.ActorSnapshotTag
85, // 167: ateapi.Control.ListWorkers:output_type -> ateapi.ListWorkersResponse
93, // 168: ateapi.Control.GetWorker:output_type -> ateapi.Worker
93, // 169: ateapi.Control.CreateWorker:output_type -> ateapi.Worker
93, // 170: ateapi.Control.UpdateWorker:output_type -> ateapi.Worker
93, // 171: ateapi.Control.DeleteWorker:output_type -> ateapi.Worker
93, // 172: ateapi.Control.DrainWorker:output_type -> ateapi.Worker
92, // 173: ateapi.Control.ListActors:output_type -> ateapi.ListActorsResponse
26, // 174: ateapi.Control.CreateAtespace:output_type -> ateapi.Atespace
26, // 175: ateapi.Control.GetAtespace:output_type -> ateapi.Atespace
55, // 176: ateapi.Control.ListAtespaces:output_type -> ateapi.ListAtespacesResponse
26, // 177: ateapi.Control.DeleteAtespace:output_type -> ateapi.Atespace
28, // 178: ateapi.Control.CreateActorTemplate:output_type -> ateapi.ActorTemplate
28, // 179: ateapi.Control.GetActorTemplate:output_type -> ateapi.ActorTemplate
60, // 180: ateapi.Control.ListActorTemplates:output_type -> ateapi.ListActorTemplatesResponse
28, // 181: ateapi.Control.DeleteActorTemplate:output_type -> ateapi.ActorTemplate
98, // 182: ateapi.ActorIdentity.MintJWT:output_type -> ateapi.MintJWTResponse
100, // 183: ateapi.ActorIdentity.MintCert:output_type -> ateapi.MintCertResponse
150, // [150:184] is the sub-list for method output_type
116, // [116:150] is the sub-list for method input_type
116, // [116:116] is the sub-list for extension type_name
116, // [116:116] is the sub-list for extension extendee
0, // [0:116] is the sub-list for field type_name
@@ -7376,9 +7295,9 @@ func file_ateapi_proto_init() {
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
RawDescriptor: unsafe.Slice(unsafe.StringData(file_ateapi_proto_rawDesc), len(file_ateapi_proto_rawDesc)),
NumEnums: 9,
NumMessages: 97,
NumMessages: 95,
NumExtensions: 0,
NumServices: 3,
NumServices: 2,
},
GoTypes: file_ateapi_proto_goTypes,
DependencyIndexes: file_ateapi_proto_depIdxs,
-11
View File
@@ -1733,17 +1733,6 @@ message ActorAssignment {
ObjectRef actor_template_ref = 4;
}
// Debug is the RPC interface for administrative and debugging operations
// (such as wiping state during development).
service Debug {
// Debugging: drop all data from the ate database.
rpc DebugClear(DebugClearRequest) returns (DebugClearResponse) {}
}
message DebugClearRequest {}
message DebugClearResponse {}
// ActorIdentity allows substrate workloads to exchange their
// infrastructure-level credentials (k8s service account token, etc.) for a
// substrate actor-level credential. A given substrate actor might migrate
-110
View File
@@ -1390,116 +1390,6 @@ var Control_ServiceDesc = grpc.ServiceDesc{
Metadata: "ateapi.proto",
}
const (
Debug_DebugClear_FullMethodName = "/ateapi.Debug/DebugClear"
)
// DebugClient is the client API for Debug service.
//
// For semantics around ctx use and closing/ending streaming RPCs, please refer to https://pkg.go.dev/google.golang.org/grpc/?tab=doc#ClientConn.NewStream.
//
// Debug is the RPC interface for administrative and debugging operations
// (such as wiping state during development).
type DebugClient interface {
// Debugging: drop all data from the ate database.
DebugClear(ctx context.Context, in *DebugClearRequest, opts ...grpc.CallOption) (*DebugClearResponse, error)
}
type debugClient struct {
cc grpc.ClientConnInterface
}
func NewDebugClient(cc grpc.ClientConnInterface) DebugClient {
return &debugClient{cc}
}
func (c *debugClient) DebugClear(ctx context.Context, in *DebugClearRequest, opts ...grpc.CallOption) (*DebugClearResponse, error) {
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
out := new(DebugClearResponse)
err := c.cc.Invoke(ctx, Debug_DebugClear_FullMethodName, in, out, cOpts...)
if err != nil {
return nil, err
}
return out, nil
}
// DebugServer is the server API for Debug service.
// All implementations must embed UnimplementedDebugServer
// for forward compatibility.
//
// Debug is the RPC interface for administrative and debugging operations
// (such as wiping state during development).
type DebugServer interface {
// Debugging: drop all data from the ate database.
DebugClear(context.Context, *DebugClearRequest) (*DebugClearResponse, error)
mustEmbedUnimplementedDebugServer()
}
// UnimplementedDebugServer must be embedded to have
// forward compatible implementations.
//
// NOTE: this should be embedded by value instead of pointer to avoid a nil
// pointer dereference when methods are called.
type UnimplementedDebugServer struct{}
func (UnimplementedDebugServer) DebugClear(context.Context, *DebugClearRequest) (*DebugClearResponse, error) {
return nil, status.Error(codes.Unimplemented, "method DebugClear not implemented")
}
func (UnimplementedDebugServer) mustEmbedUnimplementedDebugServer() {}
func (UnimplementedDebugServer) testEmbeddedByValue() {}
// UnsafeDebugServer may be embedded to opt out of forward compatibility for this service.
// Use of this interface is not recommended, as added methods to DebugServer will
// result in compilation errors.
type UnsafeDebugServer interface {
mustEmbedUnimplementedDebugServer()
}
func RegisterDebugServer(s grpc.ServiceRegistrar, srv DebugServer) {
// If the following call panics, it indicates UnimplementedDebugServer was
// embedded by pointer and is nil. This will cause panics if an
// unimplemented method is ever invoked, so we test this at initialization
// time to prevent it from happening at runtime later due to I/O.
if t, ok := srv.(interface{ testEmbeddedByValue() }); ok {
t.testEmbeddedByValue()
}
s.RegisterService(&Debug_ServiceDesc, srv)
}
func _Debug_DebugClear_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
in := new(DebugClearRequest)
if err := dec(in); err != nil {
return nil, err
}
if interceptor == nil {
return srv.(DebugServer).DebugClear(ctx, in)
}
info := &grpc.UnaryServerInfo{
Server: srv,
FullMethod: Debug_DebugClear_FullMethodName,
}
handler := func(ctx context.Context, req interface{}) (interface{}, error) {
return srv.(DebugServer).DebugClear(ctx, req.(*DebugClearRequest))
}
return interceptor(ctx, in, info, handler)
}
// Debug_ServiceDesc is the grpc.ServiceDesc for Debug service.
// It's only intended for direct use with grpc.RegisterService,
// and not to be introspected or modified (even as a copy)
var Debug_ServiceDesc = grpc.ServiceDesc{
ServiceName: "ateapi.Debug",
HandlerType: (*DebugServer)(nil),
Methods: []grpc.MethodDesc{
{
MethodName: "DebugClear",
Handler: _Debug_DebugClear_Handler,
},
},
Streams: []grpc.StreamDesc{},
Metadata: "ateapi.proto",
}
const (
ActorIdentity_MintJWT_FullMethodName = "/ateapi.ActorIdentity/MintJWT"
ActorIdentity_MintCert_FullMethodName = "/ateapi.ActorIdentity/MintCert"