Skip to content

rename ateom -> ateworker - #2254

Open
Benjamin Elder (BenTheElder) wants to merge 16 commits into
agent-substrate:mainfrom
BenTheElder:rename-ateom
Open

Benjamin Elder (BenTheElder) wants to merge 16 commits into
agent-substrate:mainfrom
BenTheElder:rename-ateom

Conversation

@BenTheElder

Copy link
Copy Markdown
Collaborator

The PR title becomes the release note. Write it for users: what changed for them, not how the code changed.

Breaking change

Renames the binaries and RPCs ahead of GA. Breaking change.

Fixes #2065

It's a good idea to open an issue first for discussion.

  • Tests pass
  • Appropriate changes to documentation are included in the PR

@wiz-alphabet

wiz-alphabet Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities -
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations 1 Medium
SAST Finding SAST Findings 4 Low
Software Management Finding Software Management Findings -
Total 1 Medium 4 Low

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio.

@BenTheElder
Benjamin Elder (BenTheElder) force-pushed the rename-ateom branch 3 times, most recently from cbdecb7 to 8964f28 Compare October 6, 2026 20:53
Comment thread benchmarking/deploy_locust.sh Outdated
echo " for each WorkerPool pod (default: unset, the pod is unsized)."
echo " --wait-timeout SECONDS Forwarded to workloads/deploy.sh. The timeout in seconds for"
echo " waiting for the ateom workers to be ready (default: 300)"
echo " waiting for the ateworker workers to be ready (default: 300)"

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So this was a direct find and replace (automated at that) but it reads weird. instead

Suggested change
echo " waiting for the ateworker workers to be ready (default: 300)"
echo " waiting for the workers to be ready (default: 300)"

@thockin Tim Hockin (thockin) left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TL;DR: the places where we just refer to the abstract idea of "a worker" should just say "worker". E.g. if someone could replace our baked-in ateworker with their own worker and the sentence would still make sense, "worker". "ateworker" should refer to specifically our main implementation(s).

But also, most of this is internal - comments etc. Focus on public facing stuff -- proto names and methods and the SPIFFE stuff.

@@ -188,7 +188,7 @@ func retryable(err error) bool {
func requestOnce(ctx context.Context, conn grpc.ClientConnInterface, actor Actor) error {
callCtx, cancel := context.WithTimeout(ctx, requestTimeout)
defer cancel()
_, err := ateletpb.NewAteomSupportClient(conn).RequestActorSuspend(callCtx, &ateletpb.RequestActorSuspendRequest{
_, err := ateletpb.NewWorkerSupportClient(conn).RequestActorSuspend(callCtx, &ateletpb.RequestActorSuspendRequest{

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In some places "Ateom" -> "Worker" and in others "AteWorker". e.g. certificateSource.MintAteWorkerCertificate(ctx) I can't discern a clear rule.

Comment thread cmd/ate-setup/internal/steps/overlay.go Outdated
// otelOverrideDeployments are the control plane Deployments that read
// ate-otel-config. ate-controller additionally copies the values onto the
// ateom worker pods it creates, so one patch reaches the whole system.
// ateworker worker pods it creates, so one patch reaches the whole system.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

super nit: "ateworker worker" -> "worker" ?

Comment thread cmd/ateapi/internal/controlapi/crash.go Outdated
crashMessageWorkerIneligible = "assigned worker no longer satisfies the actor's placement constraints"
crashMessageWorkerPodGone = "worker pod went away while hosting the actor"
crashMessageAteomRestarted = "ateom restarted while hosting the actor"
crashMessageAteWorkerRestarted = "ateworker restarted while hosting the actor"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Above says "worker pod" this says "ateworker" - I don't love embedding the word "pod" here but "worker" seems correct in both


req := &ateletpb.TerminateRequest{
TargetAteomUid: assignment.GetWorkerPodUid(),
TargetAteWorkerUid: assignment.GetWorkerPodUid(),

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here's a place where "Worker" is clearly more correct - it's the UID of the Worker resource.

// into the snapshot manifest.
req := &ateletpb.CheckpointRequest{
TargetAteomUid: assignment.GetWorkerPodUid(),
TargetAteWorkerUid: assignment.GetWorkerPodUid(),

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Another place where "Worker" is clearly more correct - it's the UID of the Worker resource.

Comment thread pkg/proto/ateapipb/ateapi.proto Outdated
// run and one more for each restart. 0 means it has not been reported.
//
// A restarted ateom has lost the sandboxes of the Actors it was hosting, so
// A restarted ateworker has lost the sandboxes of the Actors it was hosting, so

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

worker

Comment thread pkg/proto/ateapipb/ateapi.proto Outdated
@@ -2152,7 +2152,7 @@ message WorkerStatus {

// observed_epoch is the latest epoch whose earlier Actors the control plane
// has crashed and released. While it is below epoch, Actors placed before
// the ateom's last restart may still be reported as running.
// the ateworker's last restart may still be reported as running.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

worker

Comment thread pkg/proto/ateapipb/ateapi.proto Outdated
@@ -2225,19 +2225,19 @@ message ActorAssignment {
// only to an atelet, and only for the Workers on its own node.
service WorkerService {
// SetWorkerCapacity records what a Worker can hold. Capacity is the Worker's
// to report rather than the control plane's to infer: it is what the ateom
// to report rather than the control plane's to infer: it is what the ateworker

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

worker

Comment thread pkg/proto/ateapipb/ateapi.proto Outdated
// on behalf of a particular actor.
//
// SPIFFE URI: spiffe://${trustdomain}/ateom-for-actor/${atespace}/${actor}
rpc MintAteomActorCertificate(MintAteomActorCertificateRequest) returns (MintAteomActorCertificateResponse);
// SPIFFE URI: spiffe://${trustdomain}/ateworker-for-actor/${atespace}/${actor}

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a very consequential one - should SPIFFE say "ateworker" or "worker"? I think "worker".

Comment thread internal/resources/spiffe.go Outdated
return &url.URL{
Scheme: "spiffe",
Host: ActorSPIFFETrustDomain,
// TODO(identity): Prefix with "atunnel" to prevent
// confusion between atunnel and an actor pretending to be
// an atunnel.
Path: path.Join("ateom-for-actor", r.Atespace, r.Name),
Path: path.Join("ateworker-for-actor", r.Atespace, r.Name),

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Taahir Ahmed (@ahmedtd) this is a decision that will stick for a long time?

@BenTheElder

Copy link
Copy Markdown
Collaborator Author

TL;DR: the places where we just refer to the abstract idea of "a worker" should just say "worker". E.g. if someone could replace our baked-in ateworker with their own worker and the sentence would still make sense, "worker". "ateworker" should refer to specifically our main implementation(s).

Agree.

But also, most of this is internal - comments etc. Focus on public facing stuff -- proto names and methods and the SPIFFE stuff.

Yeah that makes sense, we can punt internal cleanups to later.

@BenTheElder

Copy link
Copy Markdown
Collaborator Author

I do think we should rename the internal packages to match and that's going to cause churn but we can do that separately from nailing down the user-visible renames.

@BenTheElder
Benjamin Elder (BenTheElder) force-pushed the rename-ateom branch 4 times, most recently from 722c093 to d11206d Compare October 7, 2026 03:00
ateom was named when it hosted a single actor; a worker now hosts many.
cmd/ateom-gvisor and cmd/ateom-microvm become ateworker-gvisor and
ateworker-microvm, and so do their images.
The package name is part of every method name on the wire.
Ateom becomes ateworker.Worker and AteomSupport becomes
atelet.WorkerSupport: the proto package already names the component.
AteomHerder, which ateapi calls to drive actors on a node, becomes
atelet.Atelet.
The field carries the worker pod's UID, matching worker_pod_uid in the
public API.
The certificate asserts a worker acting for an actor, whatever the worker
implementation.
ateworker is our implementation; these APIs describe any worker.
The container runs whatever image the WorkerPool names, so it is the
worker container, not necessarily an ateworker.
The phases time the worker's restore and checkpoint calls, whatever the
worker implementation.
Client-visible errors, the crash message, CRD and user docs, manifests and
the metric registry say worker for the generic concept and ateworker for
our implementation.
The keys are documented and joined by benchmarking tooling, so they
follow the binary's name.
Operators read these, so they follow the same rule as the docs.
The worker's own leaf under its container cgroup becomes worker. The
micro-VM guest's per-actor container parent becomes /actor, a name other
runtimes can share.
Per-worker directories move to /var/lib/ate/workers/<pod-uid> with a
worker.sock, and the support socket becomes worker-support.sock. The
/var/lib/ate hostPath volume is ate-base everywhere, and the capacity
volume is worker-capacity.
Covers the authz relation, e2e fixtures, benchmark names and queries,
and the remaining docs. Internal Go package names are left for later.
Code outside the ateworker binaries says worker; the binaries say
ateworker for themselves. Go package names are left for later.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Rename ateom

2 participants