Dstack-TEE / Dstack-TEE/dstack

Consider admission control for Guest Agent RPCs

オープン
#1,096 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Rust
スター
544
フォーク
96
平均マージ
17時間 57分
マージ済み PR(30日)
117

説明

## Problem

VMM proxies several API methods to the Guest Agent over vsock. Request deadlines bound how long each individual call can remain active, but they do not cap the number of calls that can execute concurrently. A burst of requests, or many unresponsive guests, could therefore create a large number of concurrent connection attempts and request tasks until their deadlines expire.

## Possible approach

Consider adding admission control at the centralized Guest Agent client boundary, with:

- a global VMM concurrency limit;
- an optional per-VM concurrency limit so one guest cannot consume the full budget;
- explicit overload behavior (fail fast versus bounded queueing);
- metrics for active calls, rejected calls, and timeout rates;
- limits derived from expected deployment size and measured resource use rather than hard-coded without capacity data.

This is intentionally tracked separately from request timeout hardening so the timeout fix remains small and the operational policy can be reviewed independently.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

No files, tests, or entry points are named. Start by locating the centralized Guest Agent client boundary and reviewing how VMM RPC calls, deadlines, and metrics are currently handled. Define the concurrency and overload policy from deployment capacity and measured resource use; done requires an agreed design covering global and per-VM limits, overload behavior, and metrics.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
rust
領域
backend-api-design, performance
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
活発
明瞭さ
説明が足りない
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。