Skip to content

Smoosh CredentialBroker and WorkerCapacity into AteomSupport - #1501

Merged
Taahir Ahmed (ahmedtd) merged 1 commit into
agent-substrate:mainfrom
ahmedtd:ateomsupport-smoosh
Sep 16, 2026
Merged

Taahir Ahmed (ahmedtd) merged 1 commit into
agent-substrate:mainfrom
ahmedtd:ateomsupport-smoosh

Conversation

@ahmedtd

@ahmedtd Taahir Ahmed (ahmedtd) commented Sep 4, 2026 •

Copy link
Copy Markdown
Collaborator

We shouldn't have a bunch of different gRPC services for atelet to provide services to ateoms. Combine the two that currently exist into one (AteomSupport).

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

second commit LGTM

Comment on lines +60 to +72
// Create a Substrate-issued JWT asserting the actor identity.
//
// * Called by the egress gateway when actor JWT injection is configured for outbound requests.
rpc MintActorJWT(MintActorJWTRequest) returns (MintActorJWTResponse) {}

// Create a Substrate-issued SPIFFE certificate asserting the actor identity.
//
// * Called by atelet to provision an atunnel with a certificate for
// communication with the egress gateway. TODO(ahmedtd): Migrate this use
// case to a distinct certificate to prevent actor/atunnel confusion.
// * Called by the egress gateway when actor client certificate injection is
// configured for outbound requests.
rpc MintActorCertificate(MintActorCertificateRequest) returns (MintActorCertificateResponse) {}

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not so sure I agree with this change. From a logical/security perspective these seem fairly different than the rest of these services. I understand that from an RBAC perspective we can treat them differently, but it can help to logically separate things which have different responsibilities.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the likely end state here is:

  • MintActorJWT/Certificate in Control API. These are called by the egress gateway, as well as customer harnesses in front of substrate, to get credentials for actions that should be undertaken as "the actor".

  • MintAteomActorCertificate in a new, atelet/ateom-focused API also served by ateapi. This would vend certs for atunnel to connect to the egress gateway. There's still some active debate on whether or not the API actually needs to be split in this way.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the specifics of what the support API look like also depend on whether atelet will still be around at GA, or if multi-actor ateoms will be connected directly to ateapi.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Strictly based on the comments above it sounds like there are open questions here which should be resolved before this PR?

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No, I think the only question is which gRPC "service" the RPCs will be in on ateapi. The actual form and purpose of the RPCs is pretty clear.

@ahmedtd

Copy link
Copy Markdown
Collaborator Author

This is now unstacked.

@ahmedtd
Taahir Ahmed (ahmedtd) merged commit 5ee4c60 into agent-substrate:main Sep 16, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants