Update to the latest version of the hack scripts (#1785)

* Fixes some minor inconsistencies
* Deletes the shell scripts (at least some of them)
* Creates a temporary shim in the old shell to call the new ate-setup
command.
This commit is contained in:
Bowei Du
2026-09-22 18:28:34 +00:00
committed by GitHub
parent 514e6109bf
commit 6c70d60c19
64 changed files with 4175 additions and 2813 deletions
@@ -1,237 +0,0 @@
#!/usr/bin/env bash
# Copyright 2026 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
# This is sourced as part of install-ate.sh. Do not run directly.
#
# --experimental-additional-egress-extproc-service=NS/SVC:PORT runs an ext_proc
# authorization filter on the egress gateway's decrypted leg, where a request is
# a hostname, method, and path rather than the IP:port the CONNECT checkpoint
# sees.
additional_egress_extproc_enabled() {
[[ -n "${ATE_ADDITIONAL_EGRESS_EXTPROC_SERVICE:-}" ]]
}
# additional_egress_extproc_endpoint validates
# --experimental-additional-egress-extproc-service and echoes the DNS name to
# dial, the port, and the name to verify the server certificate against,
# space-separated.
#
# Example input: ate-system/foo:50051
# Example output: foo.ate-system.svc.cluster.local 50051 foo.ate-system.svc
additional_egress_extproc_endpoint() {
local spec="$1"
local label='[a-z0-9]([-a-z0-9]*[a-z0-9])?'
if [[ ! "${spec}" =~ ^${label}/${label}:[0-9]+$ ]]; then
echo "Error: --experimental-additional-egress-extproc-service must be <namespace>/<service>:<port>, got '${spec}'" >&2
return 1
fi
local namespace="${spec%%/*}"
local rest="${spec#*/}"
local service="${rest%%:*}"
local port="${rest##*:}"
if (( port < 1 || port > 65535 )); then
echo "Error: --experimental-additional-egress-extproc-service port must be 1-65535, got '${port}'" >&2
return 1
fi
echo "${service}.${namespace}.svc.cluster.local ${port} ${service}.${namespace}.svc"
}
# The Envoy cluster the additional ext_proc filter dials.
readonly ADDITIONAL_EGRESS_EXTPROC_CLUSTER="additional_egress_ext_proc"
# Note: the heredoc sections are are written at column zero; the awk in
# patch_atenet_egress_manifest will re-indent to the right column.
emit_additional_egress_extproc_filter() {
cat <<EOF
# Added by hack/install-ate.sh
# --experimental-additional-egress-extproc-service=${ATE_ADDITIONAL_EGRESS_EXTPROC_SERVICE}.
# Spliced over each #ATE_MITM_EXTPROC_FILTER marker in
# atenet-egress-with-sdsmint.yaml.
- name: envoy.filters.http.ext_proc
typed_config:
"@type": type.googleapis.com/envoy.extensions.filters.http.ext_proc.v3.ExternalProcessor
grpc_service:
envoy_grpc:
cluster_name: ${ADDITIONAL_EGRESS_EXTPROC_CLUSTER}
timeout: 2s
failure_mode_allow: false
# Default is 200ms, which is tuned for the co-located sidecar
# on the CONNECT leg. This processor is a Service somewhere
# else in the cluster, and under failure_mode_allow: false a
# message that lands late is a denied request rather than a
# slow one.
message_timeout: 2s
# The actor's verified identity
request_attributes:
- filter_state['dev.ate.actor.identity']
processing_mode:
request_header_mode: SEND
response_header_mode: SKIP
request_body_mode: NONE
response_body_mode: NONE
request_trailer_mode: SKIP
response_trailer_mode: SKIP
mutation_rules:
disallow_system: true
disallow_is_error: true
EOF
}
# Arguments:
#
# $1 = address to dial
# $2 = port
# $3 = server_name to verify the server certificate against
emit_additional_egress_extproc_cluster() {
local address="$1" port="$2" server_name="$3"
cat <<EOF
# Added by hack/install-ate.sh
# --experimental-additional-egress-extproc-service=${ATE_ADDITIONAL_EGRESS_EXTPROC_SERVICE}.
# Spliced over the #ATE_MITM_EXTPROC_CLUSTER marker in
# atenet-egress-with-sdsmint.yaml.
- name: ${ADDITIONAL_EGRESS_EXTPROC_CLUSTER}
type: STRICT_DNS
lb_policy: ROUND_ROBIN
connect_timeout: 1s
# ext_proc is gRPC, so this leg has to be HTTP/2.
typed_extension_protocol_options:
envoy.extensions.upstreams.http.v3.HttpProtocolOptions:
"@type": type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions
explicit_http_config:
http2_protocol_options: {}
transport_socket:
name: envoy.transport_sockets.tls
typed_config:
"@type": type.googleapis.com/envoy.extensions.transport_sockets.tls.v3.UpstreamTlsContext
sni: ${server_name}
common_tls_context:
# Pinned, because Envoy's default ceiling for an *upstream*
# context is TLS 1.2 -- only downstream defaults to 1.3 -- while
# extprocd, like every other Go server in this install, will not
# negotiate below 1.3. Left to the defaults the two never agree,
# and the handshake fails with TLSV1_ALERT_PROTOCOL_VERSION on a
# config where both ends name TLS 1.3.
tls_params:
tls_minimum_protocol_version: TLSv1_3
tls_maximum_protocol_version: TLSv1_3
# The gateway's own pod identity, via filesystem SDS:
# watched_directory only works on SDS-delivered secrets, so an
# inline cert would never pick up kubelet's rotation.
tls_certificate_sds_secret_configs:
- name: podidentity_client_cert
sds_config:
resource_api_version: V3
path_config_source:
path: /etc/envoy/sds-podidentity-cert.yaml
combined_validation_context:
default_validation_context:
# Chaining to the servicedns CA only proves the peer is some
# pod serving some Service. Pinning the name is what makes
# this the processor the operator asked for. The flag-derived
# pin stays inline; the trust bundle rides SDS so it rotates.
match_typed_subject_alt_names:
- san_type: DNS
matcher:
exact: ${server_name}
validation_context_sds_secret_config:
name: servicedns_validation_context
sds_config:
resource_api_version: V3
path_config_source:
path: /etc/envoy/sds-servicedns-validation.yaml
load_assignment:
cluster_name: ${ADDITIONAL_EGRESS_EXTPROC_CLUSTER}
endpoints:
- lb_endpoints:
- endpoint:
address:
socket_address:
address: ${address}
port_value: ${port}
EOF
}
# patch_atenet_egress_manifest writes the egress manifest to stdout with the
# #ATE_MITM_EXTPROC_FILTER and #ATE_MITM_EXTPROC_CLUSTER marker comments in
# manifests/ate-install/atenet-egress-with-sdsmint.yaml replaced by an ext_proc
# filter -- and the cluster it dials.
#
# Only used by--experimental-additional-egress-extproc-service.
patch_atenet_egress_manifest() {
local manifest
manifest="$(atenet_egress_manifest)"
# Only the sdsmint manifest carries the markers. Refuse rather than apply an
# unpatched manifest: silently ignoring the flag would deploy a gateway with
# no additional checkpoint on it while the install reported success.
if [[ "${ATE_EXPERIMENTAL_USE_SDSMINT:-false}" != "true" ]]; then
echo "Error: --experimental-additional-egress-extproc-service requires --experimental-use-sdsmint" >&2
return 1
fi
local endpoint address port server_name
endpoint="$(additional_egress_extproc_endpoint "${ATE_ADDITIONAL_EGRESS_EXTPROC_SERVICE}")" || return 1
read -r address port server_name <<<"${endpoint}"
local filter_block cluster_block
filter_block="$(emit_additional_egress_extproc_filter)" || return 1
cluster_block="$(emit_additional_egress_extproc_cluster \
"${address}" "${port}" "${server_name}")" || return 1
local expected_filter_markers=2
# Anchored to the start of the line so that prose mentioning a marker -- the
# mitm_listener comment in the manifest names both of them -- is not itself
# replaced by a config block.
#
# Pass ATE_EXTPROC_... as env vars in ENVIRON to work around differences
# between gawk and BSD awk.
ATE_EXTPROC_FILTER_BLOCK="${filter_block}" \
ATE_EXTPROC_CLUSTER_BLOCK="${cluster_block}" \
awk -v want_filters="${expected_filter_markers}" '
BEGIN {
filter = ENVIRON["ATE_EXTPROC_FILTER_BLOCK"]
cluster = ENVIRON["ATE_EXTPROC_CLUSTER_BLOCK"]
}
/^[ \t]*#ATE_MITM_EXTPROC_FILTER/ { splice(filter); filters++; next }
/^[ \t]*#ATE_MITM_EXTPROC_CLUSTER/ { splice(cluster); clusters++; next }
{ print }
END {
if (filters != want_filters || clusters != 1) {
printf("Error: expected %d #ATE_MITM_EXTPROC_FILTER and 1 #ATE_MITM_EXTPROC_CLUSTER marker in %s, found %d and %d\n",
want_filters, FILENAME, filters, clusters) > "/dev/stderr"
exit 1
}
}
# Prints block at the indentation of the marker line being replaced. The
# heredocs above are written at column zero.
function splice(block, indent, lines, n, i) {
match($0, /^[ \t]*/)
indent = substr($0, 1, RLENGTH)
n = split(block, lines, "\n")
for (i = 1; i <= n; i++) {
print (lines[i] == "" ? "" : indent lines[i])
}
}
' "${manifest}"
}
+176 -1464
View File
File diff suppressed because it is too large Load Diff
@@ -1,70 +0,0 @@
#!/usr/bin/env bash
# Copyright 2026 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
# This is sourced as part of install-ate.sh. Do not run directly.
# This demo is kind-only: it ships its own prometheus-adapter and a kind
# specific HPA.
if [[ "${ATE_INSTALL_KIND:-false}" == "true" ]]; then
ATE_DEMOS+=(demo-autoscaled-workerpool) # register demo-autoscaled-workerpool
fi
demo-autoscaled-workerpool_cmdline() {
case "${1}" in
--deploy-demo-autoscaled-workerpool) demo-autoscaled-workerpool_deploy ;;
--delete-demo-autoscaled-workerpool) demo-autoscaled-workerpool_delete ;;
*)
ate_demo_flag_unhandled
;;
esac
}
demo-autoscaled-workerpool_deploy() {
log_step "demo-autoscaled-workerpool_deploy"
if [[ "${ATE_INSTALL_KIND:-false}" == "false" ]]; then
echo "Error: --deploy-demo-autoscaled-workerpool is not supported on GKE yet" >&2
exit 1
fi
# Deploys the pool, then creates the actor template and waits for its
# golden snapshot.
deploy_substrate_demo render_demo_manifest \
demos/autoscaled-workerpool/autoscaled-workerpool.yaml.tmpl \
ate-demo-autoscaled-workerpool counter 300 \
demos/autoscaled-workerpool/autoscaled-workerpool-template.yaml.tmpl counter
log_step "Deploying prometheus-adapter and HPA for kind..."
run_kubectl apply -f demos/autoscaled-workerpool/prometheus-adapter.yaml
run_kubectl rollout status deployment/prometheus-adapter -n ate-demo-autoscaled-workerpool --timeout=120s
run_kubectl apply -f demos/autoscaled-workerpool/hpa-kind.yaml
}
demo-autoscaled-workerpool_delete() {
log_step "demo-autoscaled-workerpool_delete"
if [[ "${ATE_INSTALL_KIND:-false}" != "true" ]]; then
echo "Error: --delete-demo-autoscaled-workerpool is not supported on GKE" >&2
exit 1
fi
# The HPA goes first so it cannot scale the pool back up while the
# workload is being removed.
run_kubectl delete --ignore-not-found -f demos/autoscaled-workerpool/hpa-kind.yaml
run_kubectl delete --ignore-not-found -f demos/autoscaled-workerpool/prometheus-adapter.yaml
delete_substrate_demo render_demo_manifest \
demos/autoscaled-workerpool/autoscaled-workerpool.yaml.tmpl \
ate-demo-autoscaled-workerpool counter
}
-105
View File
@@ -1,105 +0,0 @@
#!/usr/bin/env bash
# Copyright 2026 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
# This is sourced as part of install-ate.sh. Do not run directly.
ATE_DEMOS+=(demo-claude-code-multiplex) # register demo-claude-code-multiplex
demo-claude-code-multiplex_cmdline() {
case "${1}" in
--deploy-demo-claude-code-multiplex) demo-claude-code-multiplex_deploy ;;
--delete-demo-claude-code-multiplex) demo-claude-code-multiplex_delete ;;
*)
ate_demo_flag_unhandled
;;
esac
}
# Build the workload image, push to ${KO_DOCKER_REPO}, and echo the resolved
# digest-pinned reference (e.g. gcr.io/.../claude-multiplex-demo-workload@sha256:...).
# The workload is a Dockerfile-based Python+Claude-Code wrapper (not a Go
# binary), so it uses docker buildx rather than ko.
demo-claude-code-multiplex_build_workload() {
local repo="${KO_DOCKER_REPO}/claude-multiplex-demo-workload"
# shellcheck disable=SC2155 # safe initialization
local stage_tag="${repo}:build-$(date +%s)"
docker buildx build \
--platform=linux/amd64 \
--push \
-t "${stage_tag}" \
demos/claude-code-multiplex/workload >&2
local digest
digest=$(docker buildx imagetools inspect "${stage_tag}" --format '{{json .}}' \
| jq -r '.manifest.digest')
if [[ -z "${digest}" || "${digest}" == "null" ]]; then
echo "Failed to resolve workload image digest from ${stage_tag}" >&2
return 1
fi
echo "${repo}@${digest}"
}
# demo-claude-code-multiplex_render substitutes the demo's placeholders in a
# manifest. DEMO_CLAUDE_WORKLOAD_IMAGE is set by the deploy function after
# building the workload image; the pool manifest uses none of these values,
# so the defaults keep delete-time rendering valid without credentials.
demo-claude-code-multiplex_render() {
sed -e "s|\${BUCKET_NAME}|${BUCKET_NAME:-placeholder}|g" \
-e "s|\${ANTHROPIC_API_KEY}|${ANTHROPIC_API_KEY:-placeholder}|g" \
-e "s|\${WORKLOAD_IMAGE}|${DEMO_CLAUDE_WORKLOAD_IMAGE:-placeholder}|g" \
"$1"
}
demo-claude-code-multiplex_deploy() {
log_step "demo-claude-code-multiplex_deploy"
if [[ -z "${ANTHROPIC_API_KEY:-}" ]]; then
echo "ANTHROPIC_API_KEY must be set" >&2
return 1
fi
if [[ -z "${BUCKET_NAME:-}" ]]; then
echo "BUCKET_NAME must be set" >&2
return 1
fi
if [[ -z "${KO_DOCKER_REPO:-}" ]]; then
echo "KO_DOCKER_REPO must be set (see hack/ate-dev-env.sh.example)" >&2
return 1
fi
DEMO_CLAUDE_WORKLOAD_IMAGE=$(demo-claude-code-multiplex_build_workload)
if [[ -z "${DEMO_CLAUDE_WORKLOAD_IMAGE}" ]]; then
return 1
fi
log_step " workload image: ${DEMO_CLAUDE_WORKLOAD_IMAGE}"
deploy_substrate_demo demo-claude-code-multiplex_render \
demos/claude-code-multiplex/claude-code-multiplex.yaml.tmpl \
claude-multiplex-demo claude-workerpool 300 \
demos/claude-code-multiplex/agent-luna-template.yaml.tmpl agent-luna \
demos/claude-code-multiplex/agent-mars-template.yaml.tmpl agent-mars \
demos/claude-code-multiplex/agent-orion-template.yaml.tmpl agent-orion
}
demo-claude-code-multiplex_delete() {
log_step "demo-claude-code-multiplex_delete"
delete_substrate_demo demo-claude-code-multiplex_render \
demos/claude-code-multiplex/claude-code-multiplex.yaml.tmpl \
claude-multiplex-demo agent-luna agent-mars agent-orion
}
demo-claude-code-multiplex_usage() {
echo ""
echo " Required env: ANTHROPIC_API_KEY, BUCKET_NAME, KO_DOCKER_REPO"
echo " See demos/claude-code-multiplex/README.md for the walkthrough."
}
-111
View File
@@ -1,111 +0,0 @@
#!/usr/bin/env bash
# Copyright 2026 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
# This is sourced as part of install-ate.sh. Do not run directly.
#
# The micro-VM variant additionally needs the cluster-wide `microvm`
# SandboxConfig from hack/install-microvm-deps.sh --install.
ATE_DEMOS+=(demo-counter) # register demo-counter
demo-counter_usage() {
echo " --deploy-demo-counter-with-external-volume Deploy demo-counter with external volume validation"
echo " --deploy-demo-counter-microvm Deploy demo-counter on micro-VM workers (needs install-microvm-deps.sh)"
echo " --delete-demo-counter-microvm Delete the micro-VM variant"
}
demo-counter_cmdline() {
case "${1}" in
--deploy-demo-counter) demo-counter_deploy "false" ;;
--deploy-demo-counter-with-external-volume) demo-counter_deploy "true" ;;
--delete-demo-counter)
delete_substrate_demo demo-counter_render_plain \
demos/counter/counter.yaml.tmpl ate-demo-counter counter
;;
--deploy-demo-counter-microvm)
# 600s golden budget: a micro-VM golden is a cloud-hypervisor cold boot
# plus checkpoint, on nested KVM in CI.
deploy_substrate_demo render_demo_manifest \
demos/counter/counter-microvm.yaml.tmpl ate-demo-counter-microvm counter-microvm 600 \
demos/counter/counter-microvm-template.yaml.tmpl counter-microvm
;;
--delete-demo-counter-microvm)
delete_substrate_demo render_demo_manifest \
demos/counter/counter-microvm.yaml.tmpl ate-demo-counter-microvm counter-microvm
;;
*)
ate_demo_flag_unhandled
;;
esac
}
# demo-counter_render substitutes the demo's placeholders in a manifest:
# demo-counter_render <with_external_volume> <manifest>
# The external-volume lines are dropped unless <with_external_volume> is true.
demo-counter_render() {
local with_external_volume="$1"
local manifest="$2"
local validate_cmd=("-e" "/\${VALIDATE_EXISTING_FILE_PATH_ARG}/d")
local ext_vol_mount_cmd=("-e" "/\${EXTERNAL_VOLUME_MOUNTS}/d")
local ext_vol_spec_cmd=("-e" "/\${EXTERNAL_VOLUMES}/d")
if [[ "${with_external_volume}" == "true" ]]; then
# STORAGE_CLASS names the class outright; without it, fall back to whatever
# --setup-csi just installed, and to "standard" when it installed nothing.
local storage_class="${STORAGE_CLASS:-}"
if [[ -z "${storage_class}" ]]; then
case "${SETUP_CSI:-none}" in
hostpath) storage_class="csi-hostpath-sc" ;;
nfs|both|true) storage_class="csi-nfs-sc" ;;
*) storage_class="standard" ;;
esac
fi
validate_cmd=("-e" "s|\${VALIDATE_EXISTING_FILE_PATH_ARG}| - --validate-existing-file-path=/external-data/test.txt|g")
ext_vol_mount_cmd=("-e" "s|\${EXTERNAL_VOLUME_MOUNTS}| - name: external-data\n mountPath: /external-data|g")
ext_vol_spec_cmd=("-e" "s|\${EXTERNAL_VOLUMES}|- name: external-data\n externalVolumeTemplate:\n capacity: 1Gi\n storageClassName: ${storage_class}|g")
fi
sed -e "s|\${BUCKET_NAME}|${BUCKET_NAME}|g" \
"${validate_cmd[@]}" \
"${ext_vol_mount_cmd[@]}" \
"${ext_vol_spec_cmd[@]}" \
"${manifest}" \
| substitute_version
}
# Wrappers in the helpers' one-argument <render_fn> shape.
demo-counter_render_plain() { demo-counter_render false "$1"; }
demo-counter_render_ext_vol() { demo-counter_render true "$1"; }
demo-counter_deploy() {
local with_external_volume="${1:-false}"
log_step "demo-counter_deploy (with_external_volume=${with_external_volume})"
local render_fn=demo-counter_render_plain
if [[ "${with_external_volume}" == "true" ]]; then
render_fn=demo-counter_render_ext_vol
fi
deploy_substrate_demo "${render_fn}" \
demos/counter/counter.yaml.tmpl ate-demo-counter counter 300 \
demos/counter/counter-template.yaml.tmpl counter
}
# demo-counter_delete tears down both variants; called by delete_all.
demo-counter_delete() {
delete_substrate_demo demo-counter_render_plain \
demos/counter/counter.yaml.tmpl ate-demo-counter counter
delete_substrate_demo render_demo_manifest \
demos/counter/counter-microvm.yaml.tmpl ate-demo-counter-microvm counter-microvm
}
-149
View File
@@ -1,149 +0,0 @@
#!/usr/bin/env bash
# Copyright 2026 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
# This is sourced as part of install-ate.sh. Do not run directly.
#
# The egress demo: each variant applies a worker pool manifest, then creates
# its ActorTemplate as a substrate resource through the ate API with
# `kubectl ate create actor-template`. The micro-VM variants need the
# cluster-wide `microvm` SandboxConfig from hack/install-microvm-deps.sh
# --install; the MITM variants need an sdsmint install
# (--experimental-use-sdsmint), because their actors project the egress
# gateway trust bundle, which does not resolve otherwise.
ATE_DEMOS+=(demo-egress) # register demo-egress
# The micro-VM variant is its own demo rather than a flag on demo-egress: that
# gets it into --help and into delete_all's teardown sweep for free, and the two
# can be installed side by side (the networking suite runs against whichever the
# sandbox class under test selects).
ATE_DEMOS+=(demo-egress-microvm) # register demo-egress-microvm
# The MITM variants are separate demos for the same reason, plus one of their
# own: they project the egress gateway trust bundle, which only resolves on an
# sdsmint install, so they cannot be part of the demos a passthrough install
# deploys.
ATE_DEMOS+=(demo-egress-mitm) # register demo-egress-mitm
ATE_DEMOS+=(demo-egress-microvm-mitm) # register demo-egress-microvm-mitm
demo-egress_cmdline() {
case "${1}" in
--deploy-demo-egress) demo-egress_deploy ;;
--delete-demo-egress) demo-egress_delete ;;
*)
ate_demo_flag_unhandled
;;
esac
}
demo-egress-microvm_cmdline() {
case "${1}" in
--deploy-demo-egress-microvm) demo-egress-microvm_deploy ;;
--delete-demo-egress-microvm) demo-egress-microvm_delete ;;
*)
ate_demo_flag_unhandled
;;
esac
}
demo-egress-mitm_cmdline() {
case "${1}" in
--deploy-demo-egress-mitm) demo-egress-mitm_deploy ;;
--delete-demo-egress-mitm) demo-egress-mitm_delete ;;
*)
ate_demo_flag_unhandled
;;
esac
}
demo-egress-microvm-mitm_cmdline() {
case "${1}" in
--deploy-demo-egress-microvm-mitm) demo-egress-microvm-mitm_deploy ;;
--delete-demo-egress-microvm-mitm) demo-egress-microvm-mitm_delete ;;
*)
ate_demo_flag_unhandled
;;
esac
}
demo-egress_deploy() {
deploy_substrate_demo render_demo_manifest \
demos/egress/egress.yaml.tmpl \
ate-demo-egress egress 300 \
demos/egress/egress-template.yaml.tmpl egress
}
demo-egress_delete() {
delete_substrate_demo render_demo_manifest \
demos/egress/egress.yaml.tmpl \
ate-demo-egress egress
}
demo-egress-microvm_usage() {
echo " Needs hack/install-microvm-deps.sh --install to have run (cluster-wide microvm SandboxConfig)."
}
demo-egress-microvm_deploy() {
# 600s golden budget: a micro-VM golden is a cloud-hypervisor cold boot
# plus checkpoint, on nested KVM in CI.
deploy_substrate_demo render_demo_manifest \
demos/egress/egress-microvm.yaml.tmpl \
ate-demo-egress-microvm egress-microvm 600 \
demos/egress/egress-microvm-template.yaml.tmpl egress-microvm
}
demo-egress-microvm_delete() {
delete_substrate_demo render_demo_manifest \
demos/egress/egress-microvm.yaml.tmpl \
ate-demo-egress-microvm egress-microvm
}
demo-egress-mitm_usage() {
echo " Needs an sdsmint install (--deploy-atenet --experimental-use-sdsmint): the actors"
echo " project the egress gateway trust bundle, which does not resolve otherwise."
}
demo-egress-mitm_deploy() {
# The golden snapshot only exists once an actor starts, and an actor whose
# trust bundle does not resolve never does — so a timeout here is the
# symptom of a missing sdsmint install (see demo-egress-mitm_usage).
deploy_substrate_demo render_demo_manifest \
demos/egress/egress-mitm.yaml.tmpl \
ate-demo-egress-mitm egress-mitm 300 \
demos/egress/egress-mitm-template.yaml.tmpl egress-mitm
}
demo-egress-mitm_delete() {
delete_substrate_demo render_demo_manifest \
demos/egress/egress-mitm.yaml.tmpl \
ate-demo-egress-mitm egress-mitm
}
demo-egress-microvm-mitm_usage() {
echo " Needs hack/install-microvm-deps.sh --install to have run (cluster-wide microvm SandboxConfig),"
echo " and an sdsmint install (--deploy-atenet --experimental-use-sdsmint) for the trust bundle."
}
demo-egress-microvm-mitm_deploy() {
deploy_substrate_demo render_demo_manifest \
demos/egress/egress-microvm-mitm.yaml.tmpl \
ate-demo-egress-microvm-mitm egress-microvm-mitm 600 \
demos/egress/egress-microvm-mitm-template.yaml.tmpl egress-microvm-mitm
}
demo-egress-microvm-mitm_delete() {
delete_substrate_demo render_demo_manifest \
demos/egress/egress-microvm-mitm.yaml.tmpl \
ate-demo-egress-microvm-mitm egress-microvm-mitm
}
-46
View File
@@ -1,46 +0,0 @@
#!/usr/bin/env bash
# Copyright 2026 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
# This is sourced as part of install-ate.sh. Do not run directly.
ATE_DEMOS+=(demo-jupyter) # register demo-jupyter
demo-jupyter_usage() {
echo " --deploy-demo-jupyter Deploy demo-jupyter"
}
demo-jupyter_cmdline() {
case "${1}" in
--deploy-demo-jupyter) demo-jupyter_deploy ;;
--delete-demo-jupyter) demo-jupyter_delete ;;
*)
ate_demo_flag_unhandled
;;
esac
}
demo-jupyter_deploy() {
log_step "demo-jupyter_deploy"
deploy_substrate_demo render_demo_manifest \
demos/jupyter/jupyter.yaml.tmpl ate-demo-jupyter jupyter 300 \
demos/jupyter/jupyter-template.yaml.tmpl jupyter
}
demo-jupyter_delete() {
log_step "demo-jupyter_delete"
delete_substrate_demo render_demo_manifest \
demos/jupyter/jupyter.yaml.tmpl ate-demo-jupyter jupyter
}
-64
View File
@@ -1,64 +0,0 @@
#!/usr/bin/env bash
# Copyright 2026 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
# This is sourced as part of install-ate.sh. Do not run directly.
ATE_DEMOS+=(demo-multi-template) # register demo-multi-template
demo-multi-template_cmdline() {
case "${1}" in
--deploy-demo-multi-template) demo-multi-template_deploy ;;
--delete-demo-multi-template) demo-multi-template_delete ;;
*)
ate_demo_flag_unhandled
;;
esac
}
# The demo's two templates live in two different atespaces to show that pool
# selection is atespace-agnostic, so this composes the substrate helpers
# itself instead of using deploy_substrate_demo's one-atespace shape.
demo-multi-template_deploy() {
log_step "demo-multi-template_deploy"
ensure_crds
render_demo_manifest demos/multi-template/multi-template.yaml.tmpl \
| run_ko apply -f -
log_step "Waiting for the shared-pool worker pool rollout..."
wait_for_pool_rollout_fatal shared-pool ate-demo-multi-template-pool
ensure_atespace ate-demo-multi-template-counter
ensure_atespace ate-demo-multi-template-fspersist
create_demo_actor_template render_demo_manifest \
demos/multi-template/counter-template.yaml.tmpl \
ate-demo-multi-template-counter counter
create_demo_actor_template render_demo_manifest \
demos/multi-template/fspersist-template.yaml.tmpl \
ate-demo-multi-template-fspersist fspersist
}
demo-multi-template_delete() {
log_step "demo-multi-template_delete"
local atespace
delete_demo_actor_template ate-demo-multi-template-counter counter
delete_demo_actor_template ate-demo-multi-template-fspersist fspersist
for atespace in ate-demo-multi-template-counter ate-demo-multi-template-fspersist; do
run_kubectl_ate delete atespace "${atespace}" 2>/dev/null \
|| log_step "atespace ${atespace} not deleted (may not exist or is not empty)"
done
render_demo_manifest demos/multi-template/multi-template.yaml.tmpl \
| run_kubectl delete --ignore-not-found -f -
}
-42
View File
@@ -1,42 +0,0 @@
#!/usr/bin/env bash
# Copyright 2026 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
# This is sourced as part of install-ate.sh. Do not run directly.
ATE_DEMOS+=(demo-parking) # register demo-parking
demo-parking_cmdline() {
case "${1}" in
--deploy-demo-parking) demo-parking_deploy ;;
--delete-demo-parking) demo-parking_delete ;;
*)
ate_demo_flag_unhandled
;;
esac
}
demo-parking_deploy() {
log_step "demo-parking_deploy"
deploy_substrate_demo render_demo_manifest \
demos/parking/parking.yaml.tmpl ate-demo-parking parking 300 \
demos/parking/parking-template.yaml.tmpl parking
}
demo-parking_delete() {
log_step "demo-parking_delete"
delete_substrate_demo render_demo_manifest \
demos/parking/parking.yaml.tmpl ate-demo-parking parking
}
-42
View File
@@ -1,42 +0,0 @@
#!/usr/bin/env bash
# Copyright 2026 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
# This is sourced as part of install-ate.sh. Do not run directly.
ATE_DEMOS+=(demo-sandbox) # register demo-sandbox
demo-sandbox_cmdline() {
case "${1}" in
--deploy-demo-sandbox) demo-sandbox_deploy ;;
--delete-demo-sandbox) demo-sandbox_delete ;;
*)
ate_demo_flag_unhandled
;;
esac
}
demo-sandbox_deploy() {
log_step "demo-sandbox_deploy"
deploy_substrate_demo render_demo_manifest \
demos/sandbox/sandbox.yaml.tmpl ate-demo-sandbox sandbox-workerpool 300 \
demos/sandbox/sandbox-template.yaml.tmpl sandbox-template
}
demo-sandbox_delete() {
log_step "demo-sandbox_delete"
delete_substrate_demo render_demo_manifest \
demos/sandbox/sandbox.yaml.tmpl ate-demo-sandbox sandbox-template
}