Skip to content

Add a micro-VM variant of the sandbox demo - #2467

Open
Ziyi Tan (Ziy1-Tan) wants to merge 1 commit into
agent-substrate:mainfrom
Ziy1-Tan:sandbox-microvm-demo
Open

Ziyi Tan (Ziy1-Tan) wants to merge 1 commit into
agent-substrate:mainfrom
Ziy1-Tan:sandbox-microvm-demo

Conversation

@Ziy1-Tan

@Ziy1-Tan Ziyi Tan (Ziy1-Tan) commented Oct 11, 2026 •

Copy link
Copy Markdown

The sandbox demo's only template targets gVisor. gVisor cannot start a sandbox on
every platform, and where it cannot, the template's golden actor fails before its
snapshot is taken, which fails the deploy before any actor exists. The demo then
cannot be run at all.

Add demo-sandbox-microvm as the alternative sandbox class, in the same shape
counter and egress already carry:

 demos/sandbox/
+├── sandbox-microvm.yaml.tmpl            # WorkerPool on ateom-microvm + configRef microvm
+└── sandbox-microvm-template.yaml.tmpl   # SANDBOX_CLASS_MICROVM
 cmd/ate-setup/internal/demos/
+└── sandboxmicrovm/
+    └── sandboxmicrovm.go                # registers demo-sandbox-microvm

A reviewer can diff sandbox-microvm.yaml.tmpl against
counter-microvm.yaml.tmpl and get the whole picture. The server, the client,
and the suspend/resume behavior are untouched.

One deliberate divergence: the new pool does not pin
ate.dev/substrate-version. Only counter and counter-microvm do; egress,
jupyter, parking, multi-template, and the gVisor sandbox pool do not, and a pin
that misses the installed node label leaves the pool unschedulable.

Verified on a kind cluster. --delete-demo-sandbox-microvm && --deploy-demo-sandbox-microvm from an empty cluster exits 0, both workers reach
Running, and the golden snapshot is built. Then, through the router:

POST /process {"command":["sh","-c","echo Hello > /tmp/test.txt && cat /tmp/test.txt"]}
  → {"stdout":"Hello\n","exitCode":0}
kubectl ate suspend actor my-sandbox-1 -a ate-demo-sandbox-microvm
  → ACTOR_STATE_SUSPENDED, WORKER POD <none>
POST /process {"command":["cat","/tmp/test.txt"]}      # no explicit resume
  → {"stdout":"Hello\n","exitCode":0}
  • Tests pass: go test ./cmd/ate-setup/... (899 tests), plus the gofmt,
    boilerplate, and shellcheck verifiers.
  • Appropriate changes to documentation are included in the PR:
    demos/sandbox/README.md gains a micro-VM variant section.

@Ziy1-Tan Ziyi Tan (Ziy1-Tan) changed the title demo-sandbox-microvm: add the micro-VM variant of the sandbox demo Add a micro-VM variant of the sandbox demo Oct 11, 2026
The sandbox demo's only template targets gVisor. gVisor cannot start a sandbox
on every platform, and where it cannot, the template's golden actor fails before
its snapshot is taken, which fails the deploy before any actor exists. The demo
then cannot be run at all.

Add demo-sandbox-microvm as the alternative sandbox class, in the same shape
counter and egress already carry: a WorkerPool on ateom-microvm naming the
cluster-wide microvm SandboxConfig, plus an ActorTemplate with
SANDBOX_CLASS_MICROVM. The server, the client, and the suspend/resume behavior
are untouched.

One deliberate divergence: the new pool does not pin
ate.dev/substrate-version. Only counter and counter-microvm do; egress, jupyter,
parking, multi-template, and the gVisor sandbox pool do not, and a pin that
misses the installed node label leaves the pool unschedulable.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant