kubectl-ate: add get and create egress-policy - #1659
Conversation
7474348 to
9b308c4
Compare
5c6ffb2 to
2817215
Compare
2817215 to
2aa1c18
Compare
0f9bd53 to
dec85f6
Compare
Bowei Du (bowei)
left a comment
There was a problem hiding this comment.
Check that the help text makes sense and is relevant to the command. The help text should not talk about what Egress policy does, constraints etc.
dec85f6 to
c59d547
Compare
c59d547 to
b400a10
Compare
| ) | ||
|
|
||
| var createEgressPolicyCmd = &cobra.Command{ | ||
| Use: "egress-policy <actor-name> -f <manifest>", |
There was a problem hiding this comment.
The ability to pass a manifest and provide (atespace, name) to override it lhis looks handy for the flow where you want to copy the policy of an actor to another (otherwise you will need to store in a file, edit, call kubectl ate create). It's not consistent with ActorTemplates though, which have a similar feature. Maybe add a TODO in create_actor_template.go to add support for this as well?
There was a problem hiding this comment.
Small correction to the reading: the flags do not override the manifest. The store looks up an egress policy by ActorRef, the table's primary key is (atespace, actor_name), and the server requires metadata.name to be 'default'. On the client, --atespace and 'default' are filled in only when the manifest omits metadata, and a manifest that names a different atespace is rejected before dialing.
That means a same-atespace copy already works as a pipe: get egress-policy src -o yaml | create egress-policy dst -f -. Only a cross-atespace copy needs the manifest edited first.
I opened issue #1680 for the retarget flow, since it needs more deiscussion and design calls (silent override vs. an explicit flag, and how create actor-template should take a name).
WDYT?
0f04ffb to
cd1d2e6
Compare
d4eaf56 to
d948d03
Compare
Bowei Du (bowei)
left a comment
There was a problem hiding this comment.
Looks ok, can you look at the suggestions?
a7f2266 to
246d5dd
Compare
246d5dd to
291c344
Compare
Add `kubectl ate get egress-policy <actor> -a <atespace>` and `kubectl ate create egress-policy <actor> -a <atespace> -f <manifest>`. `get` reads the actor on a miss: a missing actor is an error, while an actor without a policy is reported on stderr with exit 0. For `create` the manifest must hold exactly one YAML document. TESTED: locally on KIND clusters
291c344 to
0fba122
Compare
Part of #1550
This PR adds
kubectl ate getandkubectl ate createsupport foregress-policy.getprints a table by default, or a bare JSON/YAML document with-o.createconsumes that same document.-f -reads stdin.metadatais filled from--atespaceand the fixed namedefault; a manifest naming another atespace is rejected before any RPC.getaccepts exactly one actor for now; a follow-up adds several actors and a list document.Recommend reviewing the four commits one at a time:
printer and manifest decoder with a round-trip test,
getcommand,createcommand,then the README updates on their own.
Tests pass:
make verifytest-egress.shstep on a local kind cluster;Appropriate changes to documentation are included in the PR.
🤖 This PR was developed with AI assistance. I have reviewed and tested all changes.