Feat/enable autoresume for byoc - #2470
Conversation
PR SummaryHigh Risk Overview Reviewed by Cursor Bugbot for commit 72f09a3. Bugbot is set up for automated code reviews on this repo. Configure here. |
# Conflicts: # packages/client-proxy/internal/proxy/paused_sandbox_resumer_grpc.go
Add a shared route IP resolver with the local-cluster fallback needed by CI, and make API/client-proxy callers treat empty resolved routes as unavailable instead of successful resume responses. This keeps BYOC/remote empty node IPs from being treated as routable while preserving the local 127.0.0.1 path.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
There are 2 total unresolved issues (including 1 from previous review).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 272b5b2. Configure here.
# Conflicts: # .env.gcp.template # iac/provider-gcp/Makefile
dobrac
left a comment
There was a problem hiding this comment.
Why using the https://github.com/coreos/go-oidc library and not the https://github.com/zitadel/oidc?
coreos/go-oidc just the minimal library for verifying the token and claims; don't really need zitadel's server |
|
ok, lets keep using the coreos one 👍 |
…l-grpc (#2631) #2470 renamed the API internal gRPC Consul service from api-grpc to api-internal-grpc. Old client-proxy allocations still have API_GRPC_ADDRESS=api-grpc.service.consul:<port> baked in and break when the old name disappears. Re-register api-grpc on the same internal port so legacy client proxies keep working during the migration. Remove once no pre-#2470 client-proxy allocations remain.

Allows edge clients to check the API for autoresume using public gRPC over TLS and the oauth jwt
This got a bit larger but does two things:
sandboxes:lifecycleNew Variables Needed:
API:
BYOC:
When a request comes into the edge proxy, if the sandbox is not present in the edge catalog, the proxy calls home to the main API to check whether it can autoresume. If it can, the API resumes the sandbox through the BYOC orchestrator and returns the node route back to the edge proxy.