Skip to content

Require atespace and actor names of at least 26 bytes - #2396

Open
Taahir Ahmed (ahmedtd) wants to merge 1 commit into
agent-substrate:mainfrom
ahmedtd:name-length-checks
Open

Taahir Ahmed (ahmedtd) wants to merge 1 commit into
agent-substrate:mainfrom
ahmedtd:name-length-checks

Conversation

@ahmedtd

@ahmedtd Taahir Ahmed (ahmedtd) commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

CreateAtespace and CreateActor now reject names shorter than 26 bytes (128 bits in base32). We can't use declarative validation because the special ate-golden namespace still needs to work.

resources.NewRandomName builds such names from crypto/rand.Text, and everything in-tree that could be converted to it has been. Some demos, and e2e tests use fixed long names, and will need deeper rework to randomly generate their names.

Docs and examples now use generated names.

Fixes #1900

Breaking change

Atespaces and actor names now must be at least 26 characters long. You are strongly suggested to use random (or at least partially-random) names, such as a UUID or the output of crypto/rand.Text().

CreateAtespace and CreateActor now reject names shorter than 26 bytes,
enough to hold 128 random bits in base-32. This pushes callers toward
random names, which are hard to squat on and are not reused once a
resource is deleted (for example, when an actor's name is referenced from
GCP Cloud IAM). No format is enforced, so a readable prefix is still
allowed. The check applies only on create: existing resources with
shorter names can still be read, updated, and deleted. The reserved
ate-golden atespace, which the template reconciler creates itself, is
exempt.

resources.NewRandomName builds such names from crypto/rand.Text, and the
in-tree tests, benchmarks, and e2e suites use it for the actors they
create. The demo, e2e fixture, and benchmark atespaces get fixed long
names, decoupled from the k8s namespaces holding their worker pools:
ate-setup waits on pool Deployments through a new steps.DeploymentRef,
and e2e fixtures map between the two with e2e.FixtureAtespace and
e2e.FixtureNamespace. Docs and examples now use generated names.
@ahmedtd

Copy link
Copy Markdown
Collaborator Author

This is a doozy since it kills every short name in the tree and adds the validation in one step. I'd focus on reviewing the validation logic, since all the other changes are just to make tests, demos, and benchmarks work with the new minimum length.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enforce minimum length requirements on atespace and actor names

1 participant