Skip to content

Unify atenet -> atunnel traffic path #1208

Description

Right now the ingress traffic paths in Substrate are a bit all over the place. Currently atenet can call into the atunnel in one of 2 ways:

  1. :443 HTTP reverse proxy: parses and authorizes every HTTP request then proxies it to the actor
  2. :444 CONNECT proxy: authorizes the CONNECT request once, opens actorIP:port, then ferries raw bytes bidirectionally.

It's not clear to me that we need the first path at all.

Parsing L7 on every request leads to worse performance overall, it is equivalent to an L7 sidecar vs the ambient model.

  1. It leads to changes such as the following which make atunnel ever more complicated.
  2. There is no current or planned L7 per request behavior we want to put in atunnel, and ideally we'd keep it that way.

Edit: One additional datapoint is that there is a design initiative right now to pack multiple actors into a single worker, see comment. The tunnel performance will become even more critical in that world.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/networkkind/cleanupSmall fixes that are not bugs, for example a typo in a code comment

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions