Commit Graph
32 Commits
Author SHA1 Message Date
Yuan Gao 1282773d3a kubectl-ate: add delete egress-policy (#1808)
Part of agent-substrate/substrate#1550.

Adds `kubectl ate delete egress-policy <actor-name> -a <atespace>`

The command removes the actor's policy. It exits 1 when the actor does
not exist
or has no policy. Also add optional `--uid` and `--version` flags, when
specified,
the server refuses the delete when either no longer matches.


### Testing

Tested on a kind cluster with the egress demo
and an API server built from this branch, using a CLI built from this
branch:

- guarded delete with a wrong version, then a wrong uid, then the right
version
- stale version after an `update` bumps the policy
- plain delete on an actor without a policy, and on an actor that does
not exist


🤖 This PR was developed with AI assistance. I have reviewed and tested
all changes.
2026-09-30 04:59:43 +00:00
Yuan Gao d7d70420db kubectl-ate: add update egress-policy (#1813)
Part of agent-substrate/substrate#1550.

Adds `kubectl ate update egress-policy <actor-name> -a <atespace> -f
<manifest>`, which replaces an actor's egress policy and prints the
result. To prevent an edit from overwriting a change made since the
read, the server rejects a manifest with `metadata.uid` and
`metadata.version` that mismatch stored ones. On NotFound the command
says whether the actor or the policy is missing; on Aborted (due to
uid/version mismatch) it points back at `get -o yaml`.

### Testing

`go test -race ./cmd/kubectl-ate/...`, `go vet`, `gofmt`. On kind: get,
edit, update round trip; stale version, missing uid and version,
atespace mismatch, and update with no policy all exit 1 with the policy
unchanged.

🤖 This PR was developed with AI assistance. I have reviewed and tested
all changes.
2026-09-24 17:51:08 +00:00
shrutiyam-glitch 47b67574ac docs: Document RevertActor and drop "terminal" from CRASHED (#1711)
`RevertActor` returns a RUNNING, PAUSED, or CRASHED actor to SUSPENDED
at its last external snapshot, so CRASHED is no longer a dead end that
only `DeleteActor` can clear. Docs and code comments still described it
as terminal and told operators to delete and recreate the actor, losing
its state.

Update the api-guide, architecture, upgrade guide, and kubectl-ate
README to cover the new verb, and correct the comments that justified
keeping a partial external snapshot by naming actor deletion as the only
remaining collector -- revert collects it too.

Follow up for the PR - #1675 
Issue - #1556 

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR
2026-09-23 17:51:56 +00:00
Yuan Gao 514e6109bf kubectl-ate: add get and create egress-policy (#1659)
Part of #1550

This PR adds `kubectl ate get` and `kubectl ate create` support for
`egress-policy`.
- `get` prints a table by default, or a bare JSON/YAML document with
`-o`.
- `create` consumes that same document. `-f -` reads stdin.
- Omitted `metadata` is filled from `--atespace` and the fixed name
`default`; a manifest naming another atespace is rejected before any
RPC.
- `get` accepts exactly one actor for now; a follow-up adds several
actors and a list document.

Recommend reviewing the four commits one at a time:
- printer and manifest decoder with a round-trip test, 
- `get` command, 
- `create` command, 
- then the README updates on their own.

- [x] Tests pass:
  - unit tests and `make verify`
- https://github.com/ygao-g/substrate/pull/33 against this head on a
local kind cluster;
  - Also tested the new `test-egress.sh` step on a local kind cluster; 
- [x] Appropriate changes to documentation are included in the PR.

🤖 This PR was developed with AI assistance. I have reviewed and tested
all changes.
2026-09-22 18:05:53 +00:00
Eitan Yarmush a58481a18e Publish ActorTemplate golden snapshots as tags (#1523)
Fixes #1507

Golden snapshots currently remain owned by the temporary golden actor,
so another resume/suspend cycle or actor deletion can collect a snapshot
still referenced by its template. The controller now copies the warmed
snapshot into a published tag, deletes the golden actor, and records the
tag reference on the template. Interrupted tag creation and cleanup
remain retryable; template deletion cleans up both resources.

`CreateActor` resolves an explicit `sourceTag` or the template's golden
tag into the actor's initial snapshot. Actors created before the golden
tag is ready retain their cold-boot behavior. The golden tag uses the
template UID as its name in `ate-golden`. The proto replaces
`golden_snapshot` with `golden_tag` at field 1, without backward
compatibility.

This PR is based directly on `main` and does not depend on #1521.

Follow-up recommendation: move the create → resume → wait → suspend →
tag → delete sequence into a golden-template workflow using the existing
workflow conventions. The reconciler now coordinates multiple
recoverable steps; it could retain scheduling and retries while
delegating that sequence to the workflow. This refactor is outside this
PR.

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR

Validation: full `env -u NO_COLOR make verify` passed after rebasing
onto `main`. After the final proto field-number change, bindings were
regenerated and the control API unit/functional tests plus proto-format
and Go-format checks passed.

---------

Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
2026-09-16 09:24:42 -04:00
Julian Gutierrez Oschmann 4003ad42d9 Some fixes to kubectl-ate CLI (#1536)
* Fix the column names to match the resource fields.
* Rename template flag name (fix TODO from CRD -> Substrate API
refactor).
* Fix bug in `create actor` which conflated the atespace flag for both
actor and actor template.
2026-09-08 12:28:51 -07:00
Luiz Oliveira 1e56e66b25 Rename ActorSnapshotTag to Tag (#1491)
Renames the proto message, its status message and scope enum, the five
RPCs and their request and response messages, the actor_snapshot_tag
request fields, and Actor.source_snapshot_tag to source_tag. The store
interface, its Postgres table, the object-storage prefix segment and the
kubectl-ate verbs follow, so nothing keeps the old spelling.

https://github.com/agent-substrate/substrate/issues/664

> It's a good idea to open an issue first for discussion.

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR
2026-09-04 18:00:36 -04:00
Luiz Oliveira 9b333c6fce Garbage Collect snapshots and remove the snapshot resource (#1417)
Fixes #664 

This PR implements the idea described in
https://github.com/agent-substrate/substrate/issues/664#issuecomment-5499311489

It does more than Garbage Collection of snapshots, because we also got
rid of the Snapshot resource (from the DB/API).

Now, an external snapshot is owned by a single resource:

- An Actor owns the snapshot it writes at suspend
- A tag owns a copy taken at tag creation,
- An actor cloned from a tag borrows the tag's snapshot until its own
first suspend.

Garbage Collection: whoever created/owns the snapshot is the only one
who ever deletes them:
i.e., if an actor is deleted and it owns a snapshot. The underlying
snapshot is deleted with the actor.

this PR:

- Drops table actor_snapshots
- Keeps table actor_snapshot_tags 
- Adds an object copy at tag creation, and an owned versus borrowed
distinction on the Actor
- Adds synchronous external snapshot deletion at actor suspend, at actor
delete, and at tag delete

> It's a good idea to open an issue first for discussion.

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR
2026-09-04 16:22:02 -04:00
Zoe Zhao f6852b7754 Update existing demos and benchmark tests to use substrate ActorTemplate resource (#1355)
This PR is very large since it updates all existing demos and benchmark
workloads to use the new ActorTemplate substrate proto.
Please use the "Commits" tab to review individual commits.

Verifications done: 
* Used this script: gpaste/5143788763348992 to verify that the change
from CRD -> proto are equivalent.
* The e2e tests are using the new susbtrate resources.
* Picked the parking demo to run e2e manually: gpaste/6193361380311040
2026-09-01 14:50:18 -07:00
Joe Betz 3efac91283 api: delete the DebugClear RPC and the Debug service (#1346)
Fixes #999.
2026-09-01 17:46:05 -04:00
Zoe Zhao 08cd74e2e0 Add kubectl ate CLI changes as well as counter demo in the new substrate resource (#1281)
* Added kubectl ate client changes for applying the counter demo.
* Added demo in both gVisor and microVM.
* Updated documentation.

Example output:

```
$ kubectl ate get actortemplates -a ate-demo-counter-substrate
ATESPACE                     NAME      SANDBOX CLASS          STATUS   AGE
ate-demo-counter-substrate   counter   SANDBOX_CLASS_GVISOR   Ready    43s

$ kubectl ate get actortemplate counter -a ate-demo-counter-substrate -o yaml
actorTemplates:
- containers:
  - command:
    - /ko-app/counter
    - --extra-port=9090
    - --tcp-port=9091
    image: gcr.io/zoezhao-gke-dev/ate-images/counter-7b2c368808ac33f45c7ab87955715526@sha256:9eb06b137bfd9f74f7ffa7c6052bb189a7b448801da81931a2124600a2622fa5
    name: counter
    readyz:
      httpGet:
        path: /readyz
        port: 80
    volumeMounts:
    - mountPath: /home/counter
      name: data
  metadata:
    atespace: ate-demo-counter-substrate
    createTime: "2026-08-28T02:09:45.981177255Z"
    name: counter
    uid: a8520ce2-f1f5-45d9-8d94-a436a72c5bf1
    updateTime: "2026-08-28T02:09:56.512455175Z"
    version: "3"
  resources:
    limits:
    - name: cpu
      quantity: "1"
    - name: memory
      quantity: 512Mi
  sandboxConfig:
    configName: gvisor-default
    sandboxClass: SANDBOX_CLASS_GVISOR
  snapshotsConfig:
    onCommit: SNAPSHOT_CONTENT_SCOPE_FULL
    onPause: SNAPSHOT_CONTENT_SCOPE_FULL
    storageLocation: gs://snapshot-substrate-test-zoezhao-gke-dev/ate-demo-counter-substrate/
  status:
    goldenSnapshotStatus:
      goldenSnapshot:
        atespace: ate-demo-counter-substrate
        name: 208d6f11-92e7-4ac0-9cab-74cd0b8a7992
      takeGoldenSnapshotAt: "2026-08-28T02:09:56.041417048Z"
  volumes:
  - durableDir: {}
    name: data
    type: DurableDir
  workerSelector:
    matchLabels:
      workload: counter-substrate
```

More testing log in gpaste/5520785792434176
2026-08-28 14:16:55 -04:00
Jet Chiang 60073ecd57 Replace ateredis with atepg (#940)
## Summary

A follow up to #640 where we introduced PostgreSQL as an alternative
storage backend, selected conditionally in ateapi.

- Deleted ateredis, its tests, and its dependencies
- Removed Redis backend selection and configuration so ateapi always
connects to Postgres
- Replaced Valkey resources with Postgres in the standard and Kind
deployment paths and simplified install script
- Replaced miniredis fixtures with isolated Postgres testcontainers and
added centralized helpers for seeding resources
- Renamed Redis-specific debug flush command to backend-neutral
`debug-clear-store` in CLI
- Updated comments and docs where applicable

## Benchmarking

Extensive benchmarking have been performed to evaluate Redis vs
Postgres, and results can be found in these two documents:

-
https://docs.google.com/document/d/10K0wB6aTeFkJCL4HN3NbLJCdFGoLYdhIcqkFnqFHkKc/edit?usp=sharing
-
https://docs.google.com/document/d/12-ko_BFHcBo_nJkx9f4B7zMbiiWKC2saGhMhZG3aQ-s/edit?usp=sharing

---------

Signed-off-by: Jet Chiang <pokyuen.jetchiang-ext@solo.io>
2026-08-25 07:23:40 -04:00
Haven Xia 640654df47 kubectl-ate: add --container log filters for actor logs (#1067)
Part of  #294 as #311 has been inactive for over a month.

Example

```
kubectl ate logs actors test -a demo                                      # default: all containers + lifecycle


kubectl ate logs actors test -a demo -c counter                           # only specified containers
```

Scoped this down to --container only after discussing with @BenTheElder
— we are not sure the naming of the container related logs, the
supervisor output may end up as a describe/events-style like how k8s
does?

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR
2026-08-21 19:06:40 -07:00
Sneha-at b7080602c6 Allow deleting an actor from any state. (#788)
Fixes #643 
This feature introduces the ability to delete Substrate actors from any
lifecycle state (e.g., RUNNING, PAUSED, PENDING), rather than requiring
them to be hibernated into SUSPENDED (or CRASHED) beforehand. This is
crucial for cleaning up stuck or failed actors.
#### 1. Control Plane & gRPC API (pkg/proto/ateapipb, ateapi)
• DeleteActorRequest.any_state: Added a new boolean field any_state to
DeleteActorRequest.
• When false (default): enforces the existing behavior where only actors
in ACTOR_STATE_SUSPENDED or ACTOR_STATE_CRASHED (or already
ACTOR_STATE_DELETING) can be deleted.
• When true: allows deleting an actor in any state (e.g., RUNNING,
PAUSED).
• Orchestrated Cleanup Workflow (workflow_delete.go):
1. Transitions actor state to ACTOR_STATE_DELETING.
2. Calls atelet.Terminate to stop live workloads on the node.
3. Detaches external volumes from the worker node (with fallback logic
using actor status if the ActorTemplate was deleted).
4. Releases the assigned physical worker Pod back to the WorkerPool.
5. Deletes external storage volumes through the storage plugins.
6. Finalizes removal of the actor from the persistence store.
#### 2. Node Herder Agent (atelet)
• Terminate RPC (main.go): Added a new Terminate method to AteomHerder:
• Calls ateom.TerminateWorkload on the target worker pod.
• Unmounts external volumes mounted for the actor on the node.
• Cleans up and resets actor runtime host directories (OCI bundles,
checkpoints, pid files).
#### 3. In-Pod Sandboxes (ateom-gvisor & ateom-microvm)
• TerminateWorkload RPC:
• gVisor (main.go): Stops and deletes active runsc containers, unmounts
bundle rootfs overlays, and tears down the actor's interior network
namespace.
• Micro-VM (checkpoint.go): Shuts down the Cloud Hypervisor VMM,
unmounts bundle rootfs overlays, and cleans up the network namespace.
• Emits an "Actor terminated" lifecycle log and clears the active actor
attribution so the worker can host new workloads.
#### 4. CLI (kubectl-ate)
• --any-state Flag (delete_actor.go):
kubectl-ate delete actor <actor-name> -a <atespace> --any-state

──────
  ## Verification 
  [x] Changes tested in local with 
 ```
• go build ./...: Passed
go test ./...: Passed (all unit and functional tests pass)
    make lint: Passed (no lint errors) 
```
Detailed manual tests                                                                                                                                                                                                                                                                                                                                           
 ```                                                                                                                                                                                                                                                                                                                                                
  ### Scenario 1: Force Delete a Running Actor with --any-state                                                                                                                                                                                                                                                                                                      
                                                                                                                                                                                                                                                                                                                                                                     
  1. Create the actor:                                                                                                                                                                                                                                                                                                                                               
    kubectl ate create actor manual-test-1 --template=ate-demo-counter-microvm/counter-microvm -a demo                                                                                                                                                                                                                                                               
                                                                                                                                                                                                                                                                                                                                                                     
  2. Resume the actor:                                                                                                                                                                                                                                                                                                                                               
    kubectl ate resume actor manual-test-1 -a demo                                                                                                                                                                                                                                                                                                                   
                                                                                                                                                                                                                                                                                                                                                                     
  3. Force delete the running actor:                                                                                                                                                                                                                                                                                                                                 
    kubectl ate delete actor manual-test-1 -a demo --any-state                                                                                                                                                                                                                                                                                                       
    actor "manual-test-1" deleted                                                                                                                                                                                                                                                                                                                                    
```
──────
### Scenario 2: Standard Delete a Suspended Actor
```                                                                                                                                                                                                                                                                                                                                  
  1. Create the actor:                                                                                                                                                                                                                                                                                                                                               
    kubectl ate create actor manual-test-2 --template=ate-demo-counter-microvm/counter-microvm -a demo                                                                                                                                                                                                                                                               
                                                                                                                                                                                                                                                                                                                                                                     
  2. Resume the actor:                                                                                                                                                                                                                                                                                                                                               
    kubectl ate resume actor manual-test-2 -a demo                                                                                                                                                                                                                                                                                                                   
                                                                                                                                                                                                                                                                                                                                                                     
  3. Suspend the actor:                                                                                                                                                                                                                                                                                                                                              
    kubectl ate suspend actor manual-test-2 -a demo                                                                                                                                                                                                                                                                                                                  
                                                                                                                                                                                                                                                                                                                                                                     
  4. Standard delete the suspended actor:                                                                                                                                                                                                                                                                                                                            
    kubectl ate delete actor manual-test-2 -a demo                                                                                                                                                                                                                                                                                                                   
    actor "manual-test-2" deleted                                                                                                                                                                                                                                                                                                                                    
```
──────
### Unit & E2E Tests
# Unit & Functional Tests
go test ./cmd/ateapi/internal/controlapi -run
"TestDeleteActorWorkflow|TestEnsureMarkedDeleting"
# E2E Tests
E2E_TEMPLATE_NAMESPACE=ate-demo-counter-microvm
E2E_TEMPLATE_NAME=counter-microvm ./hack/run-e2e-kind.sh
./internal/e2e/suites/demo -run TestActorLifecycle
./hack/run-e2e-kind.sh ./internal/e2e/suites/demo -run
TestForceDeleteActorWithExternalVolume
```
- [ x] Appropriate changes to documentation are included in the PR
2026-08-20 13:17:59 -07:00
Julian Gutierrez Oschmann 4c1bd9d36b Add status fields to Substrate resources (#1025)
Add `status` fields to all Substrate resources that need it. Move
server-owned fields under it.

Fixes #1006 .
2026-08-18 11:58:31 -07:00
Eitan Yarmush 2b3a4715c6 Configurable JWT authentication to ateapi (#757)
added configurable JWT authentication to ateapi.
2026-08-13 16:44:00 -07:00
Eitan Yarmush ef7b29da44 ateapi: add ActorSnapshot lifecycle APIs 2026-07-30 19:40:59 -07:00
Lior Lieberman 92f1aa7276 Rename SessionIdentity to ActorIdentity
Sessions are no longer a concept in Substrate; Actor is the glossary
term. This completes the "s/Session/Actor" TODO that sat at the top of
ateapi.proto, and removes the TODO.

API surface:
  service SessionIdentity        -> ActorIdentity
  MintJWTRequest.session_id      -> actor_id
  MintJWTResponse.session_jwt    -> actor_jwt
  MintCertRequest.session_id     -> actor_id
  MintCertResponse.session_certificates -> actor_certificates

Go packages:
  cmd/ateapi/internal/sessionidentity -> actoridentity
  cmd/ateapi/internal/sessionidjwt    -> actoridjwt

Flags and cluster resources:
  --session-id-jwt-pool -> --actor-id-jwt-pool
  --session-id-ca-pool  -> --actor-id-ca-pool
  Secrets, volumes and mount paths renamed to match, in both
  manifests/ate-install/ate-api-server.yaml and hack/install-ate.sh
  (--create-session-id-ca-pool-secret -> --create-actor-id-ca-pool-secret).

Two credential identity values change with the rename:
  JWT issuer https://broker.agentic-substrate-session-id-broker.svc
          -> https://broker.agentic-substrate-actor-id-broker.svc
  SPIFFE ID spiffe://substrate-session.local/app/../session/..
          -> spiffe://substrate-actor.local/app/../actor/..
Tokens and certificates issued before this change will not validate
against the new issuer or trust domain.

BREAKING: the gRPC wire path moves from /ateapi.SessionIdentity/* to
/ateapi.ActorIdentity/*, and the Secrets must be recreated under their
new names before the new ate-api-server rolls out.
2026-07-30 07:34:29 -07:00
Haven Xia 2534bf4585 kubectl-ate: filter get workers by namespace, assigned actor's atespace and selector (#588)
Should have sent out when `top worker` was added, thanks @laoj2 for
remindering!

This allow `kubectl ate get workers` to filter workers by
`-n/--namespace`, `-a/--atespace` or `-l/--selector`.


```
$ kubectl ate get workers
NAMESPACE          POOL      POD                              STATUS     ASSIGNED ACTOR
ate-demo-counter   counter   counter-worker-pool-7b9f8-x123   ASSIGNED   ate-demo-counter/counter/team-a/my-counter-1
ate-demo-counter   counter   counter-worker-pool-7b9f8-y456   FREE       <none>
ate-demo-glutton   glutton   glutton-worker-pool-5c2d1-a789   ASSIGNED   ate-demo-glutton/glutton/team-b/load-gen-1

$ kubectl ate get workers -a team-a
NAMESPACE          POOL      POD                              STATUS     ASSIGNED ACTOR
ate-demo-counter   counter   counter-worker-pool-7b9f8-x123   ASSIGNED   ate-demo-counter/counter/team-a/my-counter-1

# Scope to one WorkerPool namespace / filter by pool labels, kubectl-style
$ kubectl ate get workers -n ate-demo-counter
$ kubectl ate get workers -l ate.dev/worker-pool=counter
```

Fixes #585

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR
2026-07-29 13:29:57 -04:00
botengyao 3b58bee256 docs: fix kubectl ate logs examples and flag reference (#561)
Doc-only fix, no issue filed — happy to open one if preferred.

`-a/--atespace` became a required flag on `kubectl ate logs actors` in
#458, but the examples in the CLI README and `docs/observability.md`
were never updated. Every documented invocation currently fails:

```
$ go run ./cmd/kubectl-ate logs actors my-actor
Error: required flag(s) "atespace" not set
```

While in those files, two smaller inaccuracies in
`cmd/kubectl-ate/README.md`:

- The logs example says it "follows by default", but `--follow` defaults
to `false`. Split into a one-shot and a `-f` example.
- The global flags table was missing `--context`.

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR
2026-07-28 09:59:31 -04:00
Zoe Zhao 9890219151 Added mTLS between ate system components (#237)
Part of [#170](https://github.com/agent-substrate/substrate/issues/170)
Establishes mutual TLS between all ate system components, and updates
the certificate plumbing it depends on.

Main changes:
1. The atenet router now verifies ate apiserver' serving certificate,
and presents its client cert to ate apiserver. Previously the connection
used `InsecureSkipVerify`.
2. AteApi server verifies atelet's serving cert.

Minor bug fixes:
1. Prevent `servicednssigner` from signing a cert with no DNS SANs. Also
updated valkey cluster's cert configuration, because it was relying on
the cert with empty DNS.

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR
2026-07-24 15:43:03 -07:00
Julian Gutierrez Oschmann cbde8b19d5 Update kubectl-ate to use actor name instead of id.
This is a follow up of the API refactor. Now the CLI shows
some common fields (e.g. `create_timestamp`) but also shows
actor *name* instead of *id*.
2026-07-10 09:28:32 -07:00
mesutoezdil d7d4449693 fix: correct setup-gcp command in kubectl-ate README 2026-07-09 11:14:31 -07:00
Zoe Zhao 680dbea475 Update default GKE cluster version and enable Managed OTel feature (#352)
1) Always create a cluster with GKE Managed OpenTelemetry feature and
2) Update the default cluster version to 1.35.5-gke.1163012 which is the
current [regular channel default
version](https://docs.cloud.google.com/kubernetes-engine/docs/release-notes#current_versions)
to fix https://github.com/agent-substrate/substrate/issues/341

Tested:
* Successfully recreated GKE cluster, redeployed ate-system and ran
counter demo.
2026-06-30 16:20:05 -07:00
Haven Xia b755ae7388 Remove all the "(tenant)" description from atespace comments (#354)
followup cleaning for #280

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR
2026-06-29 22:03:25 -07:00
Haven Xia b855c3a045 Add Atespace object and CRUD API; require it on CreateActor 2026-06-29 14:57:54 -07:00
Haven Xia 756dacb953 kubectl-ate: -a shorthand for --atespace and TEMPLATE NS column 2026-06-29 14:57:54 -07:00
Haven Xia 5fdc907307 List actors across all atespaces and show ATESPACE column 2026-06-29 14:57:54 -07:00
Davanum Srinivas a88ad188d6 docs: correct stale script and template references
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2026-06-09 15:19:21 -07:00
Tim Hockin d9773e7d03 Remove trailing space from md files 2026-05-31 19:45:36 -07:00
Davanum Srinivas 5f6b627106 docs(kubectl-ate): cover kind tracing, get-column semantics, and logs (#37)
- Add a "Local (kind)" subsection alongside the existing GKE tracing
recipe.
- Add a note explaining why `kubectl get actor` and `kubectl get worker`
return nothing (they live in valkey, not as CRDs).
- Add output-column glossaries for `kubectl ate get actor` and `kubectl
ate get worker`.
- Add a "Logs" section covering the `kubectl ate logs actors <id>` form.

Fixes #<issue_number_goes_here>

> It's a good idea to open an issue first for discussion.

- [ ] Tests pass
- [x] Appropriate changes to documentation are included in the PR

Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2026-05-21 09:49:49 -04:00
+7 af3c65088e Initial commit of Agent Substrate
This is the initial release of the Agent Substrate.

Agent substrate is a system built on top of Kubernetes which manages agent-like
workloads to achieve higher scale and efficiency than Kubernetes alone can
offer, with lower latency.  It builds on top of Kubernetes features like
Pods and Pod autoscaling, but takes the Kubernetes control-plane out of the
critical path to achieve lower latency.

It can run on any Kubernetes cluster and does not inhibit “regular” use of
Kubernetes in any way. Kubernetes provides the infrastructure provisioning and
management for all types of workloads, while Agent Substrate provides
agent-specific scheduling and control.

At its core, Agent Substrate maps a larger set of “actors” (applications such
as agents) onto a smaller set of ready “workers” (Kubernetes Pods), relying on
the fact that agent-like applications tend to be idle most of the time to
achieve heavy multiplexing.  It provides functionality to manage an actor’s
lifecycle (e.g. create/destroy, suspend/resume), to assign actors to workers in real
time, and to route incoming traffic to them.

Agent Substrate is intended to be a low-opinion system.  The workloads it
manages don't have to be literal AI agents, but those are the best example of
the kind of applications it is designed for.  It is not an SDK for building
agents, but rather a system for running them at scale.

Agent Substrate is currently in VERY early development.  It is not ready for
production use, and the APIs are almost guaranteed to change.  We are not
making any guarantees about backward compatibility at this stage, and
everything in this project may be changed.

Co-authored-by: Alex Bulankou <alexbu@google.com>
Co-authored-by: Benjamin Elder <bentheelder@google.com>
Co-authored-by: Bowei Du <bowei@google.com>
Co-authored-by: Dmitry Berkovich <dberkov@google.com>
Co-authored-by: Fabricio Voznika <fvoznika@google.com>
Co-authored-by: Francisco Cabrera <fclieutier@google.com>
Co-authored-by: Haven Xia <haoyuxia@google.com>
Co-authored-by: Julian Gutierrez Oschmann <juliangut@google.com>
Co-authored-by: Kevin Steuer <ksteuer@google.com>
Co-authored-by: Max Smythe <smythe@google.com>
Co-authored-by: Maya Wang <mymaya@google.com>
Co-authored-by: Michael Taufen <mtaufen@google.com>
Co-authored-by: Shruti Nair <shrutinair@google.com>
Co-authored-by: Taahir Ahmed <taahm@google.com>
Co-authored-by: Tim Hockin <thockin@google.com>
Co-authored-by: Zoe Zhao <zoezhao@google.com>
2026-05-19 16:57:14 -07:00