agent-substrate / agent-substrate/substrate

Pluggable Egress Support

未關閉
#430 10 則留言 1 個 reaction 已指派 1 人 已被 @howardjohn 認領 在 GitHub 檢視
area/network kind/feature
主要語言
Go
星號
1.8k
分支
316
平均合併
2 天 43 分鐘
30 天內合併 PR
287

描述

We want to make it easy for users to integrate their agent policy enforcement frameworks into the substrate Actor system. Proposal for network Egress [link](https://docs.google.com/document/d/1KmpIFu2gnqy9gp95wASgIo_vkJ_dA1DZckV8upET6bs/edit), lists the following pieces:

1. Sandbox (uVM, GVisor, etc) traffic capture to a Worker or Node local proxy.
2. Local proxy for identity, metadata injection, secure redirection to PEP
3. PEP, can be outside of Substrate.

Each of these /could/ be a point of pluggability, but this is a tradeoff -- we may not need so much flexibility at this point and we do want a default install of Substrate to come with some basic functionality for real usage.

* For (1), there are precedents on how this can be done for in Pod redirection (see mesh ecosystem). One thought is that it is less about the interception itself and more about coordination with the lifecycle of the Actor, Worker and intercept, as the latency of setup is a big factor. Given this, it probably makes sense to make a "good enough" decision and move ahead.
* There is a coupling between (2) + (3), in terms of forwarding protocol. Can we assume that (2) + (3) are coupled together in most cases so the protocol is an implementation detail OR try to standardize on a protocol to decouple (2) from (3).
* One proposal is to use HTTP CONNECT as the metadata wrapper. This does not handle UDP easily, but can take care of basic HTTP.

xref:

* https://github.com/agent-substrate/substrate/issues/126.
* https://github.com/agent-substrate/substrate/pull/338/
* https://docs.google.com/document/d/1KmpIFu2gnqy9gp95wASgIo_vkJ_dA1DZckV8upET6bs/edit

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。