Skip to content

kubectl-ate: add get and create egress-policy - #1659

Merged
Bowei Du (bowei) merged 1 commit into
agent-substrate:mainfrom
ygao-g:kubectl-ate-egress-get
Sep 22, 2026
Merged

Bowei Du (bowei) merged 1 commit into
agent-substrate:mainfrom
ygao-g:kubectl-ate-egress-get

Conversation

@ygao-g

@ygao-g Yuan Gao (ygao-g) commented Sep 15, 2026 •

Copy link
Copy Markdown
Collaborator

Part of #1550

This PR adds kubectl ate get and kubectl ate create support for egress-policy.

  • get prints a table by default, or a bare JSON/YAML document with -o.
  • create consumes that same document. -f - reads stdin.
  • Omitted metadata is filled from --atespace and the fixed name default; a manifest naming another atespace is rejected before any RPC.
  • get accepts exactly one actor for now; a follow-up adds several actors and a list document.

Recommend reviewing the four commits one at a time:

🤖 This PR was developed with AI assistance. I have reviewed and tested all changes.

@ygao-g Yuan Gao (ygao-g) added area/network area/cli kind/feature An enhancement / feature request or implementation labels Sep 15, 2026
@ygao-g
Yuan Gao (ygao-g) marked this pull request as ready for review September 15, 2026 16:48
@ygao-g
Yuan Gao (ygao-g) marked this pull request as draft September 15, 2026 17:16
@ygao-g Yuan Gao (ygao-g) changed the title kubectl-ate: add get egress-policy kubectl-ate: add get and create egress-policy Sep 15, 2026
@ygao-g
Yuan Gao (ygao-g) force-pushed the kubectl-ate-egress-get branch 6 times, most recently from 5c6ffb2 to 2817215 Compare September 15, 2026 18:42
@ygao-g
Yuan Gao (ygao-g) marked this pull request as ready for review September 15, 2026 18:49
@bowei Bowei Du (bowei) self-assigned this Sep 15, 2026
@ygao-g
Yuan Gao (ygao-g) force-pushed the kubectl-ate-egress-get branch 2 times, most recently from 0f9bd53 to dec85f6 Compare September 15, 2026 22:18

@bowei Bowei Du (bowei) left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Check that the help text makes sense and is relevant to the command. The help text should not talk about what Egress policy does, constraints etc.

Comment thread cmd/kubectl-ate/internal/printer/printer.go Outdated
Comment thread cmd/kubectl-ate/internal/cmd/create_egress_policy.go Outdated
Comment thread cmd/kubectl-ate/internal/cmd/create_egress_policy.go Outdated
Comment thread cmd/kubectl-ate/internal/cmd/egress_policy.go Outdated
Comment thread cmd/kubectl-ate/internal/cmd/get_egress_policy.go Outdated
Comment thread cmd/kubectl-ate/internal/cmd/create_egress_policy.go Outdated
Comment thread cmd/kubectl-ate/internal/cmd/egress_policy.go
)

var createEgressPolicyCmd = &cobra.Command{
Use: "egress-policy <actor-name> -f <manifest>",

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The ability to pass a manifest and provide (atespace, name) to override it lhis looks handy for the flow where you want to copy the policy of an actor to another (otherwise you will need to store in a file, edit, call kubectl ate create). It's not consistent with ActorTemplates though, which have a similar feature. Maybe add a TODO in create_actor_template.go to add support for this as well?

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Small correction to the reading: the flags do not override the manifest. The store looks up an egress policy by ActorRef, the table's primary key is (atespace, actor_name), and the server requires metadata.name to be 'default'. On the client, --atespace and 'default' are filled in only when the manifest omits metadata, and a manifest that names a different atespace is rejected before dialing.

That means a same-atespace copy already works as a pipe: get egress-policy src -o yaml | create egress-policy dst -f -. Only a cross-atespace copy needs the manifest edited first.

I opened issue #1680 for the retarget flow, since it needs more deiscussion and design calls (silent override vs. an explicit flag, and how create actor-template should take a name).

WDYT?

@ygao-g
Yuan Gao (ygao-g) force-pushed the kubectl-ate-egress-get branch 2 times, most recently from d4eaf56 to d948d03 Compare September 18, 2026 16:15
Comment thread cmd/kubectl-ate/internal/cmd/egress_policy.go Outdated
Comment thread cmd/kubectl-ate/internal/cmd/egress_policy.go Outdated
Comment thread cmd/kubectl-ate/internal/cmd/egress_policy.go Outdated
Comment thread cmd/kubectl-ate/internal/cmd/egress_policy.go Outdated
Comment thread cmd/kubectl-ate/internal/cmd/egress_policy.go Outdated

@bowei Bowei Du (bowei) left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks ok, can you look at the suggestions?

@ygao-g
Yuan Gao (ygao-g) force-pushed the kubectl-ate-egress-get branch 5 times, most recently from a7f2266 to 246d5dd Compare September 21, 2026 20:10
Add `kubectl ate get egress-policy <actor> -a <atespace>` and
`kubectl ate create egress-policy <actor> -a <atespace> -f <manifest>`.

`get` reads the actor on a miss: a missing actor is an error, while
an actor without a policy is reported on stderr with exit 0. For
`create` the manifest must hold exactly one YAML document.

TESTED: locally on KIND clusters
@bowei
Bowei Du (bowei) added this pull request to the merge queue Sep 22, 2026
Merged via the queue into agent-substrate:main with commit 514e610 Sep 22, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/cli area/network kind/feature An enhancement / feature request or implementation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants