agent-substrate / agent-substrate/substrate

How should an in-cluster user-owned gateway identify an actor?

未關閉
#1,228 1 則留言 0 個 reaction 已指派 1 人 已被 @haiyanmeng 認領 在 GitHub 檢視
area/identity area/network kind/feature
主要語言
Go
星號
1.8k
分支
316
平均合併
2 天 43 分鐘
30 天內合併 PR
287

描述

**Question:**
For egress traffic from an actor to an in-cluster user-owned gateway (not Substrate's egress gateway), how should the user-owned gateway identify the actor?

**Option 1:**
@haiyanmeng did a raw exploration in #1219 by modifying the Substrate egress gateway to forward the actor identity to cluster-local origins, without realizing that token exchange is included in the [egress policy](https://docs.google.com/document/d/1s2klDhbF2mB5sslwUyZBdyXD7JqRt8FWONwJ7wgsomE/edit?tab=t.0) now.

**Option 2:**
@keithmattix and @EItanya pointed out that the token exchange feature proposed in the [egress policy](https://docs.google.com/document/d/1s2klDhbF2mB5sslwUyZBdyXD7JqRt8FWONwJ7wgsomE/edit?tab=t.0) can be a good fit for this use case.

cc @keithmattix @EItanya @LiorLieberman @bowei

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。