Skip to content

Feat/enable autoresume for byoc - #2470

Merged
matthewlouisbrockman merged 86 commits into
mainfrom
feat/byoc-autoresume
May 1, 2026
Merged

matthewlouisbrockman merged 86 commits into
mainfrom
feat/byoc-autoresume

Conversation

@matthewlouisbrockman

@matthewlouisbrockman matthewlouisbrockman commented Apr 21, 2026 •

Copy link
Copy Markdown
Contributor

Allows edge clients to check the API for autoresume using public gRPC over TLS and the oauth jwt

This got a bit larger but does two things:

  • adds a route from the edge proxies to call the API to resume sandboxes when autoresume is on
  • implements the oidc auth for the API so we can use the JWTs from edge <> our control plane
  • new scope: sandboxes:lifecycle

New Variables Needed:

API:

  • CLIENT_PROXY_OIDC_ISSUER_URL

BYOC:

  • CLIENT_PROXY_API_EDGE_GRPC_ADDRESS=grpc-api.e2b.dev:443

When a request comes into the edge proxy, if the sandbox is not present in the edge catalog, the proxy calls home to the main API to check whether it can autoresume. If it can, the API resumes the sandbox through the BYOC orchestrator and returns the node route back to the edge proxy.

                           E2B CONTROL PLANE
                     +--------------------------+
                     | API                      |
                     |                          |
                     | ResumeSandbox gRPC       |
                     | api-grpc.<domain>        |
                     |                          |
                     | Auth checks:             |
                     | - Bearer OAuth token     |
                     | - iss/aud verification   |
                     | - token org_id matches   |
                     |   cluster.auth_org_id    |
                     | - forwarded request auth |
                     |   when required          |
                     +------------+-------------+
                                  ^      |
                                  |      |
                                  |      | 3. API asks BYOC orchestrator
                                  |      |    to resume/start sandbox
                                  |      v
BYOC / EDGE DATA PLANE            |  +---------------------------+
+----------------------------------|--| edge orchestrator node   |-----------+
|                                  |  | starts/resumes sandbox   |           |
|                                  |  | updates sandbox catalog  |           |
|                                  |  +------------+--------------+           |
|                                  |               |                          |
|                                  |               | resumed sandbox           |
|                                  |               v                          |
|                                  |  +---------------------------+           |
|                                  |  | sandbox app / envd        |           |
|                                  |  +---------------------------+           |
|                                  |                                          |
|  user traffic                    |                                          |
|      |                           |                                          |
|      | optional request auth:    |                                          |
|      | - traffic access token    |                                          |
|      | - envd access token       |                                          |
|      v                           |                                          |
|  +-------------------+           |                                          |
|  | BYOC LB / DNS     |           |                                          |
|  +---------+---------+           |                                          |
|            |                     |                                          |
|            v                     |                                          |
|  +-------------------+           |                                          |
|  | edge proxy        |           |                                          |
|  | client-proxy bin  |           |                                          |
|  |                   |           |                                          |
|  | API auth:         |           |                                          |
|  | OAuth2 client     |           |                                          |
|  | credentials token |           |                                          |
|  +---------+---------+           |                                          |
|            |                     |                                          |
|            | 1. lookup sandbox   |                                          |
|            v                     |                                          |
|  +-------------------+           |                                          |
|  | edge catalog      |           |                                          |
|  | sandbox -> node   |           |                                          |
|  +----+---------+----+           |                                          |
|       |         |                |                                          |
|       | hit     | miss           |                                          |
|       |         |                |                                          |
|       |         v                |                                          |
|       |   +-------------------------------+                                 |
|       |   | 2. auto-resume path           |                                 |
|       |   | edge proxy calls API          |                                 |
|       |   | ResumeSandbox(sandbox, port)  |---------------------------------+
|       |   | over gRPC + TLS               |
|       |   |                               |
|       |   | API auth metadata:            |
|       |   | authorization: Bearer <OAuth> |
|       |   |                               |
|       |   | forwarded request metadata:   |
|       |   | x-e2b-traffic-access-token    |
|       |   | x-e2b-envd-access-token       |
|       |   +---------------+---------------+
|       |                   |
|       |                   | 4. API validates OAuth org_id
|       |                   |    against cluster.auth_org_id,
|       |                   |    validates forwarded request
|       |                   |    token if required, then
|       |                   |    returns node route
|       |                   v
|       |          +-----------------------------+
|       +--------->| edge orchestrator node      |
|                  | orchestrator proxy          |
|                  +-------------+---------------+
|                                |
|                                | 5. original request continues
|                                |    to requested sandbox port
|                                v
|                  +-----------------------------+
|                  | sandbox app / envd          |
|                  +-----------------------------+
|                                                                       |
+-----------------------------------------------------------------------+

@cursor

cursor Bot commented Apr 21, 2026 •

Copy link
Copy Markdown

PR Summary

High Risk
High risk because it introduces a new publicly reachable gRPC resume path and new OIDC/OAuth-based authorization checks that gate sandbox lifecycle actions; misconfiguration could block resumes or, worse, allow unauthorized resumes. It also changes routing/node IP selection logic across local/remote clusters, which can impact proxy traffic if edge cases return empty IPs.

Overview
Enables edge/BYOC client-proxy instances to auto-resume paused sandboxes by calling a new TLS edge gRPC listener on the API that enforces OIDC bearer-token auth (new sandboxes:lifecycle scope plus org/cluster binding via clusters.auth_org_id). This splits API gRPC into internal vs edge ports, updates client-proxy to prefer in-cluster internal gRPC but fall back to edge gRPC with OAuth2 client-credentials, and adjusts orchestrator/node discovery and routing to reliably return a routable node IP (including local CI fallbacks) while hardening token comparisons and expanding integration tests around proxy auto-resume behavior.

Reviewed by Cursor Bugbot for commit 72f09a3. Bugbot is set up for automated code reviews on this repo. Configure here.

Comment thread iac/provider-gcp/nomad-cluster/network/main.tf Outdated
Comment thread iac/provider-aws/nomad/main.tf Outdated
Comment thread packages/client-proxy/internal/proxy/proxy.go Outdated
@dobrac
dobrac requested a review from sitole April 21, 2026 22:04
Add a shared route IP resolver with the local-cluster fallback needed by CI, and make API/client-proxy callers treat empty resolved routes as unavailable instead of successful resume responses.

This keeps BYOC/remote empty node IPs from being treated as routable while preserving the local 127.0.0.1 path.
Comment thread packages/api/internal/handlers/proxy_grpc.go
Comment thread packages/api/internal/handlers/proxy_grpc.go
Comment thread packages/api/internal/oauth/oauth.go Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 2 total unresolved issues (including 1 from previous review).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 272b5b2. Configure here.

Comment thread packages/client-proxy/internal/proxy/grpc_resume_auth.go Outdated
# Conflicts:
#	.env.gcp.template
#	iac/provider-gcp/Makefile

@dobrac dobrac left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why using the https://github.com/coreos/go-oidc library and not the https://github.com/zitadel/oidc?

Comment thread packages/client-proxy/internal/proxy/paused_sandbox_resumer_grpc.go Outdated
Comment thread packages/client-proxy/internal/proxy/paused_sandbox_resumer_grpc.go Outdated
Comment thread packages/client-proxy/internal/proxy/paused_sandbox_resumer_grpc.go Outdated
@matthewlouisbrockman

Copy link
Copy Markdown
Contributor Author

Why using the https://github.com/coreos/go-oidc library and not the https://github.com/zitadel/oidc?

coreos/go-oidc just the minimal library for verifying the token and claims; don't really need zitadel's server

dobrac commented May 1, 2026

Copy link
Copy Markdown
Contributor

ok, lets keep using the coreos one 👍

@matthewlouisbrockman
matthewlouisbrockman merged commit ed90bd3 into main May 1, 2026
45 checks passed
@matthewlouisbrockman
matthewlouisbrockman deleted the feat/byoc-autoresume branch May 1, 2026 22:24
arkamar added a commit that referenced this pull request May 7, 2026
…in local dev env (#2589)

The env var was added as API_GRPC_ADDRESS in PR #2523 but the config
struct was renamed to expect API_INTERNAL_GRPC_ADDRESS in PR #2470.

Fixes: 26923df ("chore(client-proxy): set API_GRPC_ADDRESS in dev
env (#2523)")
jakubno added a commit that referenced this pull request May 12, 2026
…l-grpc (#2631)

#2470 renamed the API internal gRPC Consul service from api-grpc to
api-internal-grpc. Old client-proxy allocations still have
API_GRPC_ADDRESS=api-grpc.service.consul:<port> baked in and break when
the old name disappears. Re-register api-grpc on the same internal port
so legacy client proxies keep working during the migration. Remove once
no pre-#2470 client-proxy allocations remain.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants