There are a few cases where updating / deleting ActorTemplate resources can lead to a broken system.
- Deleting an
ActorTemplate that is currently in use by an actor breaks the ResumeActor and SuspendActor RPCs.
- If an
ActorTemplate is updated, the golden snapshot becomes stale and actors using the template diverge. Although ActorTemplates are conceptually immutable, this is not enforced today.
- Deleting an
ActorTemplate leaks its associated golden actor.
We should discuss whether we want to allow an actor to outlive its template. Assuming we don't, a possible path forward would be:
- The Substrate controller manages
ActorTemplate resources.
ActorTemplates are immutable (enforced via CEL validation).
- Each
ActorTemplate owns the lifecycle of a “golden actor”. The golden actor is created when the template is created, and deleted when the template is deleted.
- An
ActorTemplate cannot be deleted if there are actors using it (this will require ate-apiserver to expose an efficient way to check if there are active actors referencing a given template).
There are a few cases where updating / deleting ActorTemplate resources can lead to a broken system.
ActorTemplatethat is currently in use by an actor breaks theResumeActorandSuspendActorRPCs.ActorTemplateis updated, the golden snapshot becomes stale and actors using the template diverge. AlthoughActorTemplates are conceptually immutable, this is not enforced today.ActorTemplateleaks its associated golden actor.We should discuss whether we want to allow an actor to outlive its template. Assuming we don't, a possible path forward would be:
ActorTemplateresources.ActorTemplates are immutable (enforced via CEL validation).ActorTemplateowns the lifecycle of a “golden actor”. The golden actor is created when the template is created, and deleted when the template is deleted.ActorTemplatecannot be deleted if there are actors using it (this will requireate-apiserverto expose an efficient way to check if there are active actors referencing a given template).