v0.2.0 adds multi-actor workers, per-sandbox networking, and egress policy enforcement, along with many fixes and API cleanups.
Substrate is still pre-1.0 and changes quickly. This release contains breaking changes to the API and the wire protocol. Please read them below before you upgrade.
Please try it out and file issues for anything you find.
Breaking Changes
- Requests are now routed with an explicit
ate-target-actor: <atespace>/<actor>header instead of theHostheader. (#1333) ActorTemplate.containers.readyzis renamed towakeupProbe. (#1794)- The top-level
bootfield is removed fromResumeActorRequest. (#1548) IPBlockRuleis renamed toCIDRRule. (#1597)SnapshotsConfigis renamed toSnapshotConfig. (#1791)LocalSnapshotInfois renamed toLocalSnapshot. (#1856)- A worker's
sandbox_classis now immutable. (#1257) - Every
Delete<Resource>method now takesDeletePreconditions. (#1807) - The egress gateway now enforces
EgressPolicy. An actor without a policy has no egress, and traffic that no rule allows is denied. (#1545) - Actors can no longer send UDP to any port except DNS. (#1623)
- Removed the unused
TagStatus.source_actor_uidfield (#1772), other unused messages (#1814), and reserved field numbers (#1793). - Removed the
ate.scheduler.eligible_workersmetric (#1804) and the ateerrors failure-reason taxonomy (#1817). - Snapshot storage paths now use Tag UIDs. (#1521)
kubectl atenow prints a single resource as a bare object, not a list. (#1627)
Features
Workers and Actors
- A worker can now run more than one actor at a time. (#1836)
- Each actor sandbox gets its own network namespace. (#1689)
- New
RevertActorlifecycle RPC. (#1675, #1711) ActorStatusnow reports the crash reason and when it happened. (#1867)- An actor is marked crashed when an ateom checkpoint or restore fails with a non-retriable error. (#1220)
- ateom can now suspend actors itself. (#1779)
- ActorTemplate golden snapshots are published as tags. (#1523)
- ExternalSnapshot records the
actor_template_uidof each snapshot. (#1713) - The same volume can be mounted at more than one path. (#1611)
- The actor template resync interval is configurable. (#1522)
- The actor termination grace period is now 30 minutes. (#1565)
- API fields can have defaults. (#1630, #1674)
Networking and Egress
- The egress gateway enforces each actor's
EgressPolicy. (#1545) - An egress credential injector (#1360), plus an example credential provider that reads Kubernetes Secrets (#1335, #1811).
kubectl atecan get, create, and update egress policies. (#1659, #1813)- atunnel supports looking up the original destination over IPv6. (#753)
- The parking lot takes its slots when a request parks, not when it is admitted. (#1229)
- Initial Envoy Dynamic Modules for the dataplane. (#1535)
- agentgateway is tested in CI. (#1598)
Security and Identity
- Groundwork for authorization: an OpenFGA model for atespaces, served from the API server. Checks are not enforced yet. (#1233, #1670, #1839)
- Actor JWT and certificate minting moved into the API server. (#1315, #1626)
- Running actors receive rotated projected trust bundles without a restart. (#1231)
- Support for
PodCertificateRequestv1, falling back to v1beta1. Needed on clusters that no longer serve v1beta1. (#1829) - Secret-bearing proto fields are marked
debug_redactand redacted from RPC logs. (#1803, #1822) - The CSI plugin caches its CA certificate pool. (#1344)
Observability
- Actor lifecycle events are emitted over OTLP. (#1658, #1638, #1771)
- atelet emits per-actor usage events. (#1206, #1559)
- The OTLP relay forwards log records, and ateoms get a LoggerProvider over it. (#1800, #1857)
ate.worker.statereports worker occupancy in actor slots. (#1854)ate.sandbox.classis bounded by one rule for every emitter. (#1484)- Each component logs its build version at startup. (#1569)
Install and Operations
- The namespace, Service names, and ServiceAccount names are configurable. (#350)
- A large-cluster install option, and an option to run each control-plane component on a dedicated machine. (#1632)
- Tolerations to isolate workload types on tainted nodes. (#1874)
- atelet sets resource requests and a priority class. (#1651)
- The worker Deployment has an explicit rollout strategy. (#1783)
setup-gcpgains--enable-nested-virtualizationand other improvements. (#1669, #1616)- ko base images are pinned by digest. (#1500)
- Micro-VM kata assets are bumped to 4.1.0 (#1708), and the kata-config asset is dropped (#1704).
kubectl atefixes, including betterget workersoutput. (#1536, #1577, #1733)
Bug Fixes
- Fixed the kind install on arm64 hosts. (#1869)
- In-progress snapshots no longer leak after a worker is deleted. (#1541)
- atelet removes an actor's directory when it terminates the actor (#1654), and ateom removes its directory on graceful shutdown (#1678).
- ateom-gvisor deletes an actor's containers before its sandbox (#1847), treats a container runsc has no record of as already destroyed (#1666), and keys cgroup leaves by actor UID (#1667).
- ateom-gvisor names its root container
_pauseso no actor container can collide with it. (#1496) - ateom-gvisor no longer passes
-directtorunsc restore. (#1549) - ateom-microvm finds leftover VMM processes by their staged path. (#1843)
- Stale named network namespaces are replaced. (#1682)
- Stale system-info volume registrations are superseded in atelet. (#1684)
- atelet caches pool resolutions so a list flap cannot split the CPU counter. (#1479)
- The API server always resolves the atelet IP from the node name. (#1742)
- An API server replica applies its own worker writes to its cache at commit. (#1583)
- Worker pool changes now propagate to workers. (#1636)
- atenet reports "unknown" when a resume does not complete (#1482), and has a longer default route timeout (#1529).
ListActorTemplatesmaps pagination errors correctly. (#1595)- Teardown can now delete crashed actors (#942) and waits for the
ate-systemnamespace to terminate (#1851). - More validation at template creation: snapshot storage location (#1493), system-info projection paths (#1439), and container image (#1614). Added declarative validation for
TagStatusandGoldenSnapshotStatus(#1772, #1831).
Documentation
- The upgrade runbook is reorganized. (#1624)
- The supported egress traffic for GA (#1749), how the gateway enforces an EgressPolicy (#1545), and the atunnel to PEP contract (#1726).
- A metrics best-practices guide for component authors. (#1553)
- Warnings that worker node pools must not auto-upgrade or use spot nodes (#1528), and about the 30-minute eviction window (#1618).
- Added
MAINTAINERS.md(#1499), and welcomed Keith Mattix as a maintainer (#1806).
Thank you to all of our contributors.
Committers in this release include:
- Aditya Shantanu (@aditya-shantanu)
- Taahir Ahmed (@ahmedtd)
- Anna Pendleton (@annapendleton)
- Alex Zakonov (@azakonovg)
- Tim Bai (@baizhenyu)
- Benjamin Elder (@BenTheElder)
- Bowei Du (@bowei)
- Chuang Wang (@chuangw6)
- Chenyi Wang (@chw120)
- Dmitry Berkovich (@dberkov)
- Eitan Yarmush (@EItanya)
- eliranw
- Da Huang (@git286)
- haiyanmeng
- hajiler
- Haven Xia (@HavenXia)
- Huy Pham (@hdp617)
- John Howard (@howardjohn)
- Jeff Luo (@JeffLuoo)
- Jonathan Jamroga (@jjamroga)
- Joe Betz (@jpbetz)
- Julian Gutierrez Oschmann (@juli4n)
- Keith Mattix II (@keithmattix)
- Kevin Steuer (@kjsteuer)
- Krisztian F (@krisztianfekete)
- Luiz Oliveira (@laoj2)
- Lev Rado (@levrado)
- Lior Lieberman (@LiorLieberman)
- Bingtan Lu (@lubingtan)
- Max Smythe (@maxsmythe)
- Maya Wang (@mayawang)
- Michelle Au (@msau42)
- Grant McCloskey (@MushuEE)
- Nishanth Kotla (@Nishanth29)
- Omer Yahud (@omeryahud)
- NekoPunch (@orangeCatDeveloper)
- pmandewalkar
- Jaana Dogan (@rakyll)
- Ron Lev (@ronlv10)
- Sairaj Pokale (@sairajp-rewind)
- sfunkenhauser
- Shruti Nair (@SHRUTI6991)
- shrutiyam-glitch
- Sneha-at (@Sneha-at)
- Steven Shriver (@stshrive)
- Adhita Selvaraj (@swiftdiaries)
- Tim Hockin (@thockin)
- Max Thompson (@thompsonmax)
- yanavlasov
- Youssuf Elshall (@yelshall)
- Yuan Gao (@ygao-g)
- Yufan Su (@yufan-su)
- Zoe Zhao (@zoez7)