atenet

command
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 9, 2026 License: Apache-2.0 Imports: 1 Imported by: 0

README

atenet

atenet is a combined daemon for all networking functionality.

  • DNS server for ATE Actor resolution: atenet dns
  • Envoy control plane for programming ATE resolution. atenet router

This is built as a single binary for convenience in the prototyping.

Cluster deployment

router

(Note: this deployment model combines Envoy dataplane with the router. This will likely be split in the future for better scalability.)

  • atenet router will be deployed as Deployment and Service
  • Deployment will contain:
    • Envoy
    • atenet router
  • Service will expose:
    • Envoy port 80 and 443 for ordinary ingress traffic, plus a dedicated CONNECT port (8081, or 8444 for TLS) for arbitrary-port ingress: a client reaches a port on the actor other than its default (80) with an HTTP CONNECT request naming the port in the authority. Only HTTP(S) traffic over the tunnel is supported today, not raw TCP.
  • Upstream: Envoy's ORIGINAL_DST actor cluster dials the actor's in-worker atunnel ingress server on the worker pod's port 443 over mTLS, using the address atenet router's ext_proc resolves into dynamic metadata rather than a header. atunnel can't read that metadata directly, though -- it's a separate process on the worker pod, not part of Envoy -- so the port to reach on the actor itself (its default port, or an arbitrary one for CONNECT) still travels as a real header, atunnel.TargetPortHeader. :authority/Host reaches atunnel unmodified either way, so it authorizes the actor by its own DNS name.
  • Termination: the router drains gracefully on SIGTERM (readiness flip → endpoint propagation → Envoy admin-API drain → ext_proc drain), and the Envoy container's preStop hook waits for the router's drain-complete marker on a pod-shared emptyDir — so established connections and parked requests finish instead of resetting. The whole sequence must fit within terminationGracePeriodSeconds (see the manifest comments). Upgrades are whole-system swaps (#473) rather than per-Deployment rolling updates; the drain is what makes the old system's termination lossless.

RBAC permissions:

  • get, list, watch on ate-system EndpointSlices
dns
  • atenet dns will be deployed as:

    • Deployment
    • Service exposing tcp and udp 53
  • read, list on kube-system services

  • read, list on ate-system services

testing

Run the package tests with go test ./cmd/atenet/.... Cluster e2e tests use the shared hack/run-e2e.sh runner.

Documentation

The Go Gopher

There is no documentation for this package.

Directories

Path Synopsis
dns
router/egress
Package egress implements the ext_proc handler for outbound actor traffic: it authenticates the actor behind an egress CONNECT before the gateway tunnels it out.
Package egress implements the ext_proc handler for outbound actor traffic: it authenticates the actor behind an egress CONNECT before the gateway tunnels it out.
router/extproc
Package extproc implements the external processing (ext_proc) gRPC server that the atenet router serves to its dataplane gateways.
Package extproc implements the external processing (ext_proc) gRPC server that the atenet router serves to its dataplane gateways.
router/ingress
Package ingress implements the ext_proc handler for traffic arriving at the ingress gateway: it resolves the actor a request is addressed to, resumes it through the control plane (parking the request while the worker pool is saturated), and points the dataplane at the worker that ends up hosting it.
Package ingress implements the ext_proc handler for traffic arriving at the ingress gateway: it resolves the actor a request is addressed to, resumes it through the control plane (parking the request while the worker pool is saturated), and points the dataplane at the worker that ends up hosting it.
sdsmint
Delta SDS: the stateful, per-connection half of the server.
Delta SDS: the stateful, per-connection half of the server.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL