Similar to the WorkerPoolSyncer today, I think we should also sync SandboxConfig object to the substrate API.
SandboxConfigs are infrastructure resources that are managed by platform operators:
|
3. **Governance**: Keeping infrastructure resources (WorkerPools, |
|
SandboxConfigs) as Kubernetes objects allows platform teams to apply |
|
familiar RBAC, auditing, and policy enforcement to the underlying |
|
infrastructure, while workload definitions (ActorTemplates) are managed |
|
through the substrate API instead, which authenticates callers itself |
|
but does not yet implement authorization (see |
|
[authentication.md](authentication.md)). |
However when clients call CreateActorTemplate, they may need to specify which SandboxConfig object to use, which means clients need to first call ListSandboxConfigs API to discover the available SandboxConfig objects to use.
Similar to the WorkerPoolSyncer today, I think we should also sync
SandboxConfigobject to the substrate API.SandboxConfigs are infrastructure resources that are managed by platform operators:
substrate/docs/architecture.md
Lines 255 to 261 in 74bbfc5
However when clients call
CreateActorTemplate, they may need to specify which SandboxConfig object to use, which means clients need to first call ListSandboxConfigs API to discover the available SandboxConfig objects to use.