Update agentgateway implementation - #28
Merged
Merged
Conversation
keithmattix
commented
Sep 1, 2026
keithmattix
force-pushed
the
wire-up-agw-e2es
branch
from
September 1, 2026 23:03
ea4c4c9 to
bf3fbff
Compare
keithmattix
commented
Sep 1, 2026
EItanya
force-pushed
the
main
branch
4 times, most recently
from
September 2, 2026 17:46
07b8a46 to
243ec3e
Compare
keithmattix
force-pushed
the
wire-up-agw-e2es
branch
2 times, most recently
from
September 3, 2026 12:58
1949b14 to
4d476b2
Compare
keithmattix
commented
Sep 3, 2026
keithmattix
force-pushed
the
wire-up-agw-e2es
branch
from
September 3, 2026 14:36
4167fa7 to
b06dc43
Compare
keithmattix
marked this pull request as draft
September 4, 2026 15:21
EItanya
force-pushed
the
main
branch
2 times, most recently
from
September 9, 2026 13:09
2900564 to
a7505e9
Compare
Add e2e.RouterIsAgentgateway, detected from the atenet-router Deployment's containers, and gate the Envoy-only assertions on it: the h2-to-h1 downgrade contract is Envoy's protocol mirroring to atunnel, which agentgateway does not implement.
Bump agentgateway to a nightly that authorizes the actor identity before terminating any CONNECT tunnel and retries stale worker assignments on the CONNECT leg by evicting and re-resolving through ResumeActor. substrateEgress accordingly moves from a policy on the internal HTTP route to frontendPolicies in the egress ConfigMaps (manifests component, MITM overlay, and the Helm chart): the frontend check covers HTTP, TLS, and opaque TCP tunnels alike, where the old route policy silently exempted the TLS and TCP passthrough routes. This closes the hole where a certificate for an unknown actor could open a tunnel, and makes suspended actors resumable through the router again.
The e2e-test job's install step waits for each ate-system workload with the script's default 60s rollout timeout. That default assumes warm image caches; on a fresh CI runner every image (postgres, the agentgateway proxy for both router and egress, ...) is cold-pulled from public registries concurrently, and the first wait in line regularly exceeds 60s on pull latency alone. Give the install a 300s per-workload budget, matching the tolerance the helm-e2e workflow already has.
helm-e2e waited for condition=Ready on the counter-microvm ActorTemplate CRD after deploying the demo. The cutover to the substrate ActorTemplate proto removed the CRD golden flow and then the CRD itself, so the wait can never succeed. The demo deploy now creates the substrate template and waits for its golden snapshot internally, so drop the separate wait step and point the micro-VM test lane at the substrate fixtures with the E2E_SANDBOX_CLASS knob pr-workflow already uses.
keithmattix
force-pushed
the
wire-up-agw-e2es
branch
from
September 10, 2026 18:11
b06dc43 to
9e6f325
Compare
keithmattix
marked this pull request as ready for review
September 10, 2026 18:24
EItanya
approved these changes
Sep 10, 2026
Pick up the latest agentgateway nightly. The frontend policy that authorizes egress at CONNECT-accept was renamed upstream from substrateEgress to substrateEgressActorResolution, and the old key now fails config parsing, so rename it in the manifests and the chart in the same step.
keithmattix
force-pushed
the
wire-up-agw-e2es
branch
from
September 10, 2026 19:48
3ab9dbd to
44bd15a
Compare
EItanya
pushed a commit
that referenced
this pull request
Sep 10, 2026
Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
This was referenced Sep 10, 2026
teemow
added a commit
to giantswarm/substrate
that referenced
this pull request
Sep 11, 2026
…e — the line's dataplane (agentgateway#3237) reads it there (#9) * chart: authorize the egress actor as a frontend policy at CONNECT time agentgateway#3237 moved the actor check on an egress tunnel from a route policy on the inner HTTP listener to a frontend policy on the CONNECT itself (substrateEgress under frontendPolicies) and dropped the route-level field. A dataplane carrying it refuses the previous config ("unknown field `substrateEgress`") and never becomes ready. The egress config now declares the policy where that dataplane reads it, and images.agentgateway pins a build that carries #3237. The two move together: the previous build accepts only the route-level shape, and a build without #3237 knows neither the frontend field nor the check. Same change as kagent-dev#28 for a later dataplane, where the policy carries the name agentgateway#3318 gave it, substrateEgressActorResolution. * ci(fork): the publish refuses a drift between the chart's images.agentgateway and AGENTGATEWAY_IMAGE; ledger row for the frontend-policy egress config
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Not fully working with all upstream substrate tests, but trying to unblock some of the other work