Skip to content

v0.2.0

Latest

Choose a tag to compare

@BenTheElder BenTheElder released this 25 Sep 22:26
10a1bfb

v0.2.0 adds multi-actor workers, per-sandbox networking, and egress policy enforcement, along with many fixes and API cleanups.

Substrate is still pre-1.0 and changes quickly. This release contains breaking changes to the API and the wire protocol. Please read them below before you upgrade.

Please try it out and file issues for anything you find.

Breaking Changes

  • Requests are now routed with an explicit ate-target-actor: <atespace>/<actor> header instead of the Host header. (#1333)
  • ActorTemplate.containers.readyz is renamed to wakeupProbe. (#1794)
  • The top-level boot field is removed from ResumeActorRequest. (#1548)
  • IPBlockRule is renamed to CIDRRule. (#1597)
  • SnapshotsConfig is renamed to SnapshotConfig. (#1791)
  • LocalSnapshotInfo is renamed to LocalSnapshot. (#1856)
  • A worker's sandbox_class is now immutable. (#1257)
  • Every Delete<Resource> method now takes DeletePreconditions. (#1807)
  • The egress gateway now enforces EgressPolicy. An actor without a policy has no egress, and traffic that no rule allows is denied. (#1545)
  • Actors can no longer send UDP to any port except DNS. (#1623)
  • Removed the unused TagStatus.source_actor_uid field (#1772), other unused messages (#1814), and reserved field numbers (#1793).
  • Removed the ate.scheduler.eligible_workers metric (#1804) and the ateerrors failure-reason taxonomy (#1817).
  • Snapshot storage paths now use Tag UIDs. (#1521)
  • kubectl ate now prints a single resource as a bare object, not a list. (#1627)

Features

Workers and Actors

  • A worker can now run more than one actor at a time. (#1836)
  • Each actor sandbox gets its own network namespace. (#1689)
  • New RevertActor lifecycle RPC. (#1675, #1711)
  • ActorStatus now reports the crash reason and when it happened. (#1867)
  • An actor is marked crashed when an ateom checkpoint or restore fails with a non-retriable error. (#1220)
  • ateom can now suspend actors itself. (#1779)
  • ActorTemplate golden snapshots are published as tags. (#1523)
  • ExternalSnapshot records the actor_template_uid of each snapshot. (#1713)
  • The same volume can be mounted at more than one path. (#1611)
  • The actor template resync interval is configurable. (#1522)
  • The actor termination grace period is now 30 minutes. (#1565)
  • API fields can have defaults. (#1630, #1674)

Networking and Egress

  • The egress gateway enforces each actor's EgressPolicy. (#1545)
  • An egress credential injector (#1360), plus an example credential provider that reads Kubernetes Secrets (#1335, #1811).
  • kubectl ate can get, create, and update egress policies. (#1659, #1813)
  • atunnel supports looking up the original destination over IPv6. (#753)
  • The parking lot takes its slots when a request parks, not when it is admitted. (#1229)
  • Initial Envoy Dynamic Modules for the dataplane. (#1535)
  • agentgateway is tested in CI. (#1598)

Security and Identity

  • Groundwork for authorization: an OpenFGA model for atespaces, served from the API server. Checks are not enforced yet. (#1233, #1670, #1839)
  • Actor JWT and certificate minting moved into the API server. (#1315, #1626)
  • Running actors receive rotated projected trust bundles without a restart. (#1231)
  • Support for PodCertificateRequest v1, falling back to v1beta1. Needed on clusters that no longer serve v1beta1. (#1829)
  • Secret-bearing proto fields are marked debug_redact and redacted from RPC logs. (#1803, #1822)
  • The CSI plugin caches its CA certificate pool. (#1344)

Observability

  • Actor lifecycle events are emitted over OTLP. (#1658, #1638, #1771)
  • atelet emits per-actor usage events. (#1206, #1559)
  • The OTLP relay forwards log records, and ateoms get a LoggerProvider over it. (#1800, #1857)
  • ate.worker.state reports worker occupancy in actor slots. (#1854)
  • ate.sandbox.class is bounded by one rule for every emitter. (#1484)
  • Each component logs its build version at startup. (#1569)

Install and Operations

  • The namespace, Service names, and ServiceAccount names are configurable. (#350)
  • A large-cluster install option, and an option to run each control-plane component on a dedicated machine. (#1632)
  • Tolerations to isolate workload types on tainted nodes. (#1874)
  • atelet sets resource requests and a priority class. (#1651)
  • The worker Deployment has an explicit rollout strategy. (#1783)
  • setup-gcp gains --enable-nested-virtualization and other improvements. (#1669, #1616)
  • ko base images are pinned by digest. (#1500)
  • Micro-VM kata assets are bumped to 4.1.0 (#1708), and the kata-config asset is dropped (#1704).
  • kubectl ate fixes, including better get workers output. (#1536, #1577, #1733)

Bug Fixes

  • Fixed the kind install on arm64 hosts. (#1869)
  • In-progress snapshots no longer leak after a worker is deleted. (#1541)
  • atelet removes an actor's directory when it terminates the actor (#1654), and ateom removes its directory on graceful shutdown (#1678).
  • ateom-gvisor deletes an actor's containers before its sandbox (#1847), treats a container runsc has no record of as already destroyed (#1666), and keys cgroup leaves by actor UID (#1667).
  • ateom-gvisor names its root container _pause so no actor container can collide with it. (#1496)
  • ateom-gvisor no longer passes -direct to runsc restore. (#1549)
  • ateom-microvm finds leftover VMM processes by their staged path. (#1843)
  • Stale named network namespaces are replaced. (#1682)
  • Stale system-info volume registrations are superseded in atelet. (#1684)
  • atelet caches pool resolutions so a list flap cannot split the CPU counter. (#1479)
  • The API server always resolves the atelet IP from the node name. (#1742)
  • An API server replica applies its own worker writes to its cache at commit. (#1583)
  • Worker pool changes now propagate to workers. (#1636)
  • atenet reports "unknown" when a resume does not complete (#1482), and has a longer default route timeout (#1529).
  • ListActorTemplates maps pagination errors correctly. (#1595)
  • Teardown can now delete crashed actors (#942) and waits for the ate-system namespace to terminate (#1851).
  • More validation at template creation: snapshot storage location (#1493), system-info projection paths (#1439), and container image (#1614). Added declarative validation for TagStatus and GoldenSnapshotStatus (#1772, #1831).

Documentation

  • The upgrade runbook is reorganized. (#1624)
  • The supported egress traffic for GA (#1749), how the gateway enforces an EgressPolicy (#1545), and the atunnel to PEP contract (#1726).
  • A metrics best-practices guide for component authors. (#1553)
  • Warnings that worker node pools must not auto-upgrade or use spot nodes (#1528), and about the 30-minute eviction window (#1618).
  • Added MAINTAINERS.md (#1499), and welcomed Keith Mattix as a maintainer (#1806).

Thank you to all of our contributors.

Committers in this release include: