Skip to content

Workspace clones run in the golden boot, where Substrate blocks egress #427

Description

@eren23

What happens: Substrate boots each new ActorTemplate once, as a temporary golden actor in the ate-golden atespace, and snapshots it. The runner prepares workspaces in that boot. A default Substrate install denies all actor egress until the actor has an EgressPolicy. A task policy cannot apply to the golden actor. So every Workspace git clone fails, and the task still reports WorkspaceReady.

Evidence (kind install, AX d0bc38b, Substrate 1d7ca8c):

  • In the task, PID 1 (ax-task-runner) started at the template creation time, and /ax/git-error.log shows the failed fetch.
  • git clone in the task gives gnutls_handshake() failed: The TLS connection was non-properly terminated.
  • The egress gateway logs egress denied: actor has no egress policy.

Suggested fix: Document the egress requirement. Let AX create or reference an EgressPolicy for the golden boot. Or prepare workspaces on the first boot of the real actor.

Environment: google/ax d0bc38b and Agent Substrate 1d7ca8c, on a local kind cluster (Docker Desktop on Apple Silicon).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions