Egress support#11
Draft
npolshakova wants to merge 5 commits into
Draft
Conversation
* wip - publish release * release yaml
* router: add pluggable networking providers * make websockets work in agw, make agw default in install script Signed-off-by: Peter Jausovec <peter.jausovec@solo.io> --------- Signed-off-by: Peter Jausovec <peter.jausovec@solo.io> Co-authored-by: John Howard <john.howard@solo.io> Co-authored-by: Peter Jausovec <peter.jausovec@solo.io>
* enable websockets (agent-substrate#4) Signed-off-by: Peter Jausovec <peter.jausovec@solo.io> Co-authored-by: Peter Jausovec <peter.jausovec@solo.io> * feat: allow running with vanilla k8s - add a helm chart - allow JWT auth instead of mTLS * update helm chart images * fix rbac. note that JWT verification is not cached and might not work on some k8s distributions that not expose the JWKS * fix: add chart boilerplate headers * fix: support jwt helm install on plain kind * feat: add substrate crds helm chart * feat: make jwt helm installs standalone * fix: make helm defaults cloud-neutral * fix: sync crd chart templates * fix: use agentgateway in helm chart * fix: update agentgateway install overlays * fix: project agentgateway tls key separately --------- Signed-off-by: Peter Jausovec <peter.jausovec@solo.io> Co-authored-by: Eitan Yarmush <eitan.yarmush@solo.io> Co-authored-by: Peter Jausovec <peter.jausovec@solo.io>
Closed
0775bd7 to
c2536ed
Compare
6d7b14d to
a3b8f7f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Draft prototype for agent-substrate#126 with agentgateway.
Goal is to start with ActorTemplate.spec.egressPolicy only and focus on workload-intent use cases. We may later want to add standalone EgressPolicy later when global, namespace, or actor-specific policy becomes necessary.
Testing
Setup
Create actor:
Port-forward router:
With this egress policy on ActorTemplate:
Request to http://example.com/ or https://example.com/ will work:
But other requests will get 502:
The logs will show the egress policy is resolved: