agent-substrate / agent-substrate/substrate

Pluggable Egress Support

未关闭
#430 10 条评论 1 个 reaction 已指派 1 人 已被 @howardjohn 认领 在 GitHub 查看
area/network kind/feature
主要语言
Go
星标
1.8k
派生
316
平均合并
2 天 43 分钟
30 天内合并 PR
287

描述

We want to make it easy for users to integrate their agent policy enforcement frameworks into the substrate Actor system. Proposal for network Egress [link](https://docs.google.com/document/d/1KmpIFu2gnqy9gp95wASgIo_vkJ_dA1DZckV8upET6bs/edit), lists the following pieces:

1. Sandbox (uVM, GVisor, etc) traffic capture to a Worker or Node local proxy.
2. Local proxy for identity, metadata injection, secure redirection to PEP
3. PEP, can be outside of Substrate.

Each of these /could/ be a point of pluggability, but this is a tradeoff -- we may not need so much flexibility at this point and we do want a default install of Substrate to come with some basic functionality for real usage.

* For (1), there are precedents on how this can be done for in Pod redirection (see mesh ecosystem). One thought is that it is less about the interception itself and more about coordination with the lifecycle of the Actor, Worker and intercept, as the latency of setup is a big factor. Given this, it probably makes sense to make a "good enough" decision and move ahead.
* There is a coupling between (2) + (3), in terms of forwarding protocol. Can we assume that (2) + (3) are coupled together in most cases so the protocol is an implementation detail OR try to standardize on a protocol to decouple (2) from (3).
* One proposal is to use HTTP CONNECT as the metadata wrapper. This does not handle UDP easily, but can take care of basic HTTP.

xref:

* https://github.com/agent-substrate/substrate/issues/126.
* https://github.com/agent-substrate/substrate/pull/338/
* https://docs.google.com/document/d/1KmpIFu2gnqy9gp95wASgIo_vkJ_dA1DZckV8upET6bs/edit

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。