What happens: Substrate boots each new ActorTemplate once, as a temporary golden actor in the ate-golden atespace, and snapshots it. The runner prepares workspaces in that boot. A default Substrate install denies all actor egress until the actor has an EgressPolicy. A task policy cannot apply to the golden actor. So every Workspace git clone fails, and the task still reports WorkspaceReady.
Evidence (kind install, AX d0bc38b, Substrate 1d7ca8c):
- In the task, PID 1 (
ax-task-runner) started at the template creation time, and /ax/git-error.log shows the failed fetch.
git clone in the task gives gnutls_handshake() failed: The TLS connection was non-properly terminated.
- The egress gateway logs
egress denied: actor has no egress policy.
Suggested fix: Document the egress requirement. Let AX create or reference an EgressPolicy for the golden boot. Or prepare workspaces on the first boot of the real actor.
Environment: google/ax d0bc38b and Agent Substrate 1d7ca8c, on a local kind cluster (Docker Desktop on Apple Silicon).
What happens: Substrate boots each new ActorTemplate once, as a temporary golden actor in the
ate-goldenatespace, and snapshots it. The runner prepares workspaces in that boot. A default Substrate install denies all actor egress until the actor has anEgressPolicy. A task policy cannot apply to the golden actor. So every Workspacegitclone fails, and the task still reportsWorkspaceReady.Evidence (kind install, AX
d0bc38b, Substrate1d7ca8c):ax-task-runner) started at the template creation time, and/ax/git-error.logshows the failed fetch.git clonein the task givesgnutls_handshake() failed: The TLS connection was non-properly terminated.egress denied: actor has no egress policy.Suggested fix: Document the egress requirement. Let AX create or reference an
EgressPolicyfor the golden boot. Or prepare workspaces on the first boot of the real actor.Environment: google/ax
d0bc38band Agent Substrate1d7ca8c, on a local kind cluster (Docker Desktop on Apple Silicon).