mirror of
https://github.com/agent-substrate/substrate.git
synced 2026-10-02 03:24:42 +08:00
Move to lowercase for header references
Signed-off-by: Keith Mattix II <keithmattix2@gmail.com>
This commit is contained in:
committed by
Bowei Du
parent
9adfb35962
commit
6bd89588dc
+2
-2
@@ -144,7 +144,7 @@ Container environment variables support literal `value` entries only. Values are
|
||||
### Workload Connectivity
|
||||
|
||||
A higher-order system reaches an actor through the **Substrate Router** by
|
||||
setting `Ate-Target-Actor` to `<atespace>/<actor>`. Substrate does not provide
|
||||
setting `ate-target-actor` to `<atespace>/<actor>`. Substrate does not provide
|
||||
DNS discovery for actors. This value selects the Actor; `Host` and HTTP/2
|
||||
`:authority` remain application metadata. Normal HTTP requirements still apply:
|
||||
clients must send a valid `Host` or `:authority`, usually derived automatically
|
||||
@@ -163,7 +163,7 @@ authority. With curl, use `--proxy-header` instead of `-H`:
|
||||
|
||||
```bash
|
||||
curl --proxytunnel --proxy http://localhost:8001 \
|
||||
--proxy-header "Ate-Target-Actor: my-atespace/my-actor" \
|
||||
--proxy-header "ate-target-actor: my-atespace/my-actor" \
|
||||
http://actor-upstream:9090/
|
||||
```
|
||||
|
||||
|
||||
@@ -343,7 +343,7 @@ Handles actor-aware routing and automatic re-animation.
|
||||
|
||||
* **Ingress Routing**: `atenet-router` runs Envoy with an `ext_proc` external
|
||||
processor. A higher-order system connects to the router and supplies the
|
||||
Actor target in `Ate-Target-Actor` as `<atespace>/<actor>`.
|
||||
Actor target in `ate-target-actor` as `<atespace>/<actor>`.
|
||||
The ext_proc calls the Control Plane to resume the Actor and resolve its
|
||||
current worker assignment. `Host` remains application authority and does
|
||||
not select the Actor.
|
||||
@@ -382,7 +382,7 @@ sequenceDiagram
|
||||
participant A as Actor
|
||||
participant Store as snapshot storage
|
||||
|
||||
Client->>Gateway: HTTP request (Ate-Target-Actor)
|
||||
Client->>Gateway: HTTP request (ate-target-actor)
|
||||
Gateway->>API: ResumeActor(atespace, actor name)
|
||||
API->>Atelet: Restore
|
||||
Store-->>Atelet: download snapshot
|
||||
@@ -509,7 +509,7 @@ Agent Substrate is built on a **Defense-in-Depth** model:
|
||||
versions.
|
||||
|
||||
* **Request Authorization**: The system currently performs **Identity-Aware
|
||||
Routing** by extracting and validating the `Ate-Target-Actor` header at
|
||||
Routing** by extracting and validating the `ate-target-actor` header at
|
||||
the gateway. This ensures requests are only
|
||||
routed to recognized, registered actors.
|
||||
Pluggable, granular authorization policies are planned for future
|
||||
|
||||
+1
-1
@@ -158,5 +158,5 @@ for etcd.
|
||||
## Networking
|
||||
|
||||
- **Actor routing header**: a higher-order system sends traffic to the
|
||||
Substrate router with `Ate-Target-Actor: <atespace>/<actor>`. The router
|
||||
Substrate router with `ate-target-actor: <atespace>/<actor>`. The router
|
||||
uses this header to locate and resume the Actor.
|
||||
|
||||
+1
-1
@@ -44,7 +44,7 @@ Below is a collection of finer-grained efforts which we believe align with the a
|
||||
|
||||
* Actor security boundary implementation, default deny with explicit ACLs at scale with low latency. This overlaps with some of the security items (see below).
|
||||
* Policy definition: between framework (outside) and Actors, between Actors, Actor Egress.
|
||||
* Actor-to-actor routing through explicit identity headers.
|
||||
* Actor-to-actor routing through explicit actor-reference headers.
|
||||
|
||||
### Storage
|
||||
|
||||
|
||||
@@ -39,8 +39,8 @@ Substrate is an early, fast moving product. It is full of debate and subject to
|
||||
* **Worker:** Preprovisioned Pods that actors get scheduled to.
|
||||
* **Actor:** The core compute primitive, gets scheduled to/from worker via Run for cold start and Resume for snapshot resume.
|
||||
* **Actor Network:** `ateom` creates a private point-to-point veth network for the active Actor inside a worker Pod. The Actor is not served directly from the worker Pod's port 80; ingress enters through `atunnel`'s authenticated listener on port 443.
|
||||
* **Actor Routing:** Requests sent to `atenet-router` identify the target Actor with `Ate-Target-Actor: <atespace>/<actor>`. Host and authority values are application metadata and do not select the Actor.
|
||||
* **atenet-router:** Substrate runs Envoy with an `ext_proc` external processor to handle Actor ingress. The ext_proc reads and validates `Ate-Target-Actor`, calls the Substrate API to resume the Actor and obtain its current worker assignment, and selects that worker as a dynamic backend. It overwrites the routing header before forwarding. The router then connects with mTLS to `atunnel`; `atunnel` validates the router identity and authorizes the header against the Actor currently assigned to that worker.
|
||||
* **Actor Routing:** Requests sent to `atenet-router` identify the target Actor with `ate-target-actor: <atespace>/<actor>`. Host and authority values are application metadata and do not select the Actor.
|
||||
* **atenet-router:** Substrate runs Envoy with an `ext_proc` external processor to handle Actor ingress. The ext_proc reads and validates `ate-target-actor`, calls the Substrate API to resume the Actor and obtain its current worker assignment, and selects that worker as a dynamic backend. It overwrites the routing header before forwarding. The router then connects with mTLS to `atunnel`; `atunnel` validates the router identity and authorizes the header against the Actor currently assigned to that worker.
|
||||
* **Object Storage:** Used to store actor snapshots.
|
||||
* **Filesystem support:** Container local filesystem is saved in snapshots, future integrations likely to include networked storage.
|
||||
* **Substrate Database:** PostgreSQL. On GCP, PostgreSQL may be Cloud SQL reached through the Cloud SQL Auth Proxy sidecar (see [tools/setup-gcp/cloud-sql.md](../tools/setup-gcp/cloud-sql.md)); that path adds two egress flows from ate-api-server: HTTPS to `sqladmin.googleapis.com:443` and the proxy tunnel to the instance IP on port 3307, both authenticated via IAM and encrypted.
|
||||
|
||||
Reference in New Issue
Block a user