Conversation
There is a get and a create verb for an actor's egress policy, but no way to change one short of calling UpdateActorEgressPolicy directly. Add "kubectl ate update egress-policy <actor> -a <atespace> -f <manifest>". The RPC takes the policy's uid and version as preconditions. A manifest that sets both, as "get -o yaml" output does, sends them as is, so a concurrent change fails the update. A manifest that sets neither is applied over whatever the current policy is: the command reads it first and uses its uid and version. Setting only one of the two is rejected. As with get, a NotFound is resolved into "actor not found" or "actor has no egress policy" by reading the actor.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
agent-substrate/substrate#1659 added
kubectl ate getandcreate egress-policy, but an existing policycan only be changed by calling
UpdateActorEgressPolicydirectly. This adds:The RPC takes the policy's
uidandversionas preconditions:get -o yamloutput does): they're sent as is,so the update fails if the policy changed since it was read.
its
uidandversion, replacing it whatever its version.As with
get, aNotFoundis resolved into "actor not found" or "actor has noegress policy" by reading the actor. The second points at
create.Manifest parsing and metadata defaulting reuse the
createpath. The README'sEgress Policies section documents the new verb.
Tests:
preconditions sent as is, a half-set precondition, an actor with no policy,
a missing actor, a policy deleted between read and update, and a read failure.
go vetandgolangci-lintpass oncmd/kubectl-ate.