Skip to content

kubectl-ate: add update egress-policy - #2

Open
oldsj wants to merge 1 commit into
mainfrom
upstream/egress-policy-update
Open

oldsj wants to merge 1 commit into
mainfrom
upstream/egress-policy-update

Conversation

@oldsj

@oldsj oldsj commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

agent-substrate/substrate#1659 added kubectl ate get and create egress-policy, but an existing policy
can only be changed by calling UpdateActorEgressPolicy directly. This adds:

kubectl ate update egress-policy <actor-name> -a <atespace> -f policy.yaml

The RPC takes the policy's uid and version as preconditions:

  • The manifest sets both (as get -o yaml output does): they're sent as is,
    so the update fails if the policy changed since it was read.
  • The manifest sets neither: the command reads the current policy and uses
    its uid and version, replacing it whatever its version.
  • Only one is set: rejected.

As with get, a NotFound is resolved into "actor not found" or "actor has no
egress policy" by reading the actor. The second points at create.

Manifest parsing and metadata defaulting reuse the create path. The README's
Egress Policies section documents the new verb.

Tests:

  • Unit tests for the runner: preconditions taken from the current policy,
    preconditions sent as is, a half-set precondition, an actor with no policy,
    a missing actor, a policy deleted between read and update, and a read failure.
  • Argument tests for the new command.
  • go vet and golangci-lint pass on cmd/kubectl-ate.
  • Not yet run against a live control plane.

There is a get and a create verb for an actor's egress policy, but no way
to change one short of calling UpdateActorEgressPolicy directly. Add
"kubectl ate update egress-policy <actor> -a <atespace> -f <manifest>".

The RPC takes the policy's uid and version as preconditions. A manifest
that sets both, as "get -o yaml" output does, sends them as is, so a
concurrent change fails the update. A manifest that sets neither is applied
over whatever the current policy is: the command reads it first and uses
its uid and version. Setting only one of the two is rejected. As with get,
a NotFound is resolved into "actor not found" or "actor has no egress
policy" by reading the actor.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant