Repository navigation
Conversation
Signed-off-by: Ayush Sawant <ayush.sawant@nutanix.com>
✅ Deploy Preview for theagentrouter ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
Signed-off-by: Ayush Sawant <ayush.sawant@nutanix.com>
Signed-off-by: Ayush Sawant <ayush.sawant@nutanix.com>
Signed-off-by: Ayush Sawant <ayush.sawant@nutanix.com>
|
@AyushSawant18588 could you fix the tests? |
|
One gap in the deletion change, which I ran into while working on the That can happen two ways:
I checked the first case with a controller test that creates and reconciles a Keeping |
Signed-off-by: Ayush Sawant <ayush.sawant@nutanix.com>
vignesh-chaturvedi
left a comment
There was a problem hiding this comment.
Thanks for picking this up. I checked out ff1c427 and ran the controller tests:
everything passes, and putting the not-found branch back to a bare return fails
all three new deletion tests, so they cover the gap. LGTM for the deletion path.
It also covers the second case I raised. handleFinalizer drops the callback's
error and removes the finalizer anyway, so if the cleanup or the notification in
the callback fails, the not-found reconcile now retries both and requeues on
error. In a normal deletion both paths run, which is safe since each step is
idempotent.
Small nit, in line with aabchoo's helper suggestion on ai_gateway_route.go:
notifyAIGatewayRoutesForNamespace builds the index key with
fmt.Sprintf("%s.%s", ...) as well, so it could use the same helper.
Since notifyAIGatewayRoutesForNamespace and the three new deletion tests are
carried over from #2770, would you mind adding
Co-authored-by: Vignesh Chaturvedi <vigneshchaturvedi@gmail.com> to the PR
description so it ends up in the squash commit? Thanks!
…etRef updates Signed-off-by: Ayush Sawant <ayush.sawant@nutanix.com>
Signed-off-by: Ayush Sawant <ayush.sawant@nutanix.com>
|
Thanks for adding the credit! One small thing: GitHub only links a co-author That's the same format earlier squash merges here use. Thanks again! |
Done. Can you approve if PR looks good? |
Signed-off-by: Ayush Sawant <ayush.sawant@nutanix.com>
Description
When a QuotaPolicy CR was updated, the new configuration was not applied to the data plane until the AI Gateway controller and the Envoy proxy pod were restarted.
The root cause is that a QuotaPolicy feeds two config planes: the rate limit service config (the numeric limits, pushed over xDS) and the Envoy data-plane config (the rate limit filter, cluster, and per-route descriptors, injected by the extension server's PostTranslateModify). The extension server only runs when Envoy Gateway re-translates, which happens when a resource it watches changes. QuotaPolicy is not such a resource. The controller tried to force re-translation by re-reconciling the HTTPRoute, but the regenerated HTTPRoute was identical (its content does not depend on the QuotaPolicy), so the update was a no-op and Envoy Gateway never re-translated.
This change stamps a hash of the applicable QuotaPolicy specs onto the generated HTTPRoute as the aigateway.envoyproxy.io/quota-policy-hash annotation (mirroring the existing stampGatewayConfigHash approach for GatewayConfig). A QuotaPolicy create/update/delete now changes the annotation, making the HTTPRoute genuinely change, which forces Envoy Gateway to re-translate and re-run PostTranslateModify with the latest policy. The hash covers each policy's full spec, so both value-only changes (e.g. a limit bump) and structural changes (e.g. a new model or bucket rule) are picked up live.
This change also fixes QuotaPolicy deletion not propagating to routes in different namespace. Deleting a QuotaPolicy now notifies the referencing AIGatewayRoutes (via the finalizer callback, while TargetRefs are still available) so their generated HTTPRoutes are re-stamped and Envoy Gateway re-translates without the deleted policy, no controller/Envoy restart required. The quota-policy-hash computation also skips terminating policies (non-zero DeletionTimestamp), closing the issue where a cached, soon-to-be-deleted policy could otherwise leave the hash unchanged.
Unit tests cover the hash computation and annotation behavior, and an e2e test verifies the annotation changes when a QuotaPolicy is updated live (no restart).
Manually tested the changes end to end by deploying the updated AI Gateway controller and updating and deleting Quota Policy and verify the changes being translated properly in Envoy config
Co-authored-by: Vignesh Chaturvedi vigneshchaturvedi@gmail.com