agent-substrate / agent-substrate/substrate

Consider removing custom DNS for actors

Aberta
#445 5 comentários 0 reações 1 responsável Reivindicada por @bowei Ver no GitHub
area/network kind/cleanup
Linguagem predominante
Go
Estrelas
1.8k
Forks
316
Merge médio
2d 43min
PRs com merge (30d)
287

Descrição

Currently we rely on a fairly wonky controller that rewrites CoreDNS or other providers (https://github.com/agent-substrate/substrate/issues/348) to add the '.substrate.ate.dev' single wildcard -> IP domain. This works but it doesn't feel great.

* This targets one/two DNS provider, but there are many we will need to add
* This makes subtrate responsible for reconciling a kubernetes system resource, that will quite plausibly get reconciled back by the core cluster infrastructure.
* Modifying only the cluster-local DNS means I cannot resolve it outside of the cluster
* 'my-counter-1.demo.actors.resources.substrate.ate.dev' style naming means we have two wildcards. DNS allows a single wildcard to cover multiple labels, but TLS doesn't. This means I cannot serve a `*.actors.resources.substrate.ate.dev` TLS cert.

One option briefly discussed was using paths identify the actor. For example `curl atenet.svc.cluster.local/actors/demo/my-counter/some/path` would forward to 'my-counter' in 'demo' atespace and send to /some/path. One possible concern with this is it looks us into HTTP (unless we start doing CONNECT or something). Today, we are only implementing HTTP but the design would at least facilitate TLS as we could do SNI routing; moving to path based would remove that possibility.

Guia de contribuição

Abrir o guia de contribuição

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.