Skip to content

feat: migrate AKernel sandbox backend to Agent DX - #78

Draft
WenYuLuo wants to merge 7 commits into
inclusionAI:mainfrom
WenYuLuo:feat/adx-backend
Draft

WenYuLuo wants to merge 7 commits into
inclusionAI:mainfrom
WenYuLuo:feat/adx-backend

Conversation

@WenYuLuo

@WenYuLuo WenYuLuo commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Migrate AKernel's Sandbox backend to Agent DX while preserving the existing Python SDK configuration and public command, file, PTY, port-forwarding, checkpoint and reload interfaces.

  • Keep the SDK address/token contract and legacy backend selector aliases. No caller configuration migration is required.
  • Package a checksum-pinned ADX release and SDK wheel. AKernel continues to own sandboxd and the runtime rootfs; the runtime image consumes the ADX RRT binary.
  • Replace the legacy control plane with ADX coordinator, gateway, and node roles for standalone and Kubernetes deployment. Internal mTLS remains optional for the AKernel integration.
  • Keep standalone control and data traffic on separate ports while allowing gateway components to share a process. Traefik is no longer required for standalone.
  • Preserve workload-triggered checkpoint through the RRT Unix socket and SDK reload to the saved recovery point.
  • Add tiered functional, fault, performance, and scale test drivers plus deployment and validation documentation.

Commit organization

The branch is organized into six signed-off commits by responsibility:

  1. 4e84df8 feat(sdk): migrate sandbox backend to ADX
  2. 5652b03 build(adx): package the pinned backend runtime
  3. 813f4f6 feat(deploy): replace legacy control plane with ADX
  4. c919cb6 test(adx): add tiered end-to-end acceptance
  5. 00366f3 perf(adx): add scalable workload benchmarks
  6. ba25285 docs(adx): document deployment and validation

Runtime provenance

  • AKernel commit: ba2528573b279f7e741d8e53f81dca0d5a765eaf
  • ADX commit: 5e62b9f3fd571bd4d796380e07269976bbb1d820
  • ADX Buildkite: #124, passed
  • ADX release source: https://openyuanrong.obs.cn-southwest-2.myhuaweicloud.com/adx/daily/20260929023150-5e62b9f3fd57/linux/amd64/
  • sandboxd pin: 31d0749a85e269396cfc1c469c948345f9610906
  • Validated AKernel image: swr.cn-north-4.myhuaweicloud.com/openyuanrong/cluster-all-in-one@sha256:9da5ac35c3dddb413911f4fa8c93074216d0a7bfd7df6d1a96ddd1a446399469
  • Image OCI revision: ba2528573b279f7e741d8e53f81dca0d5a765eaf

Validation

  • Local SDK and benchmark regression: 268 SDK unit tests and 30 benchmark tests passed; Ruff, mypy, deployment contract checks, shell syntax and diff checks passed.
  • GitHub Actions run 36518156479: Python 3.10-3.14, SDK lint/type/distributions, deployment contracts and Standalone E2E all passed.
  • Final Linux standalone E2E against the digest above: 12/12 groups completed; 11 passed and runtime integration completed with one declared expected skip. Cleanup removed the container and listeners on ports 29443 and 29080.
  • Final cn-north-4 Kubernetes E2E in namespace akernel: 31 groups, 66 tests, 0 failed and 0 timed out. 23 groups passed, 3 were expected partial, and 5 destructive/maintenance fault groups were explicitly skipped.
    • Partial coverage is limited by environment assets: heterogeneous runtime inventory, a Host routing test domain, S3 fixtures, a short-lived OCI entrypoint image, and a GPU worker.
    • Six product Pods were Ready with restart count 0 and the exact validated image digest.
    • The run created no new Redis residue and left no held environment. The cluster had one pre-existing Failed Environment before the run and the same record after the run; the regression did not delete unrelated pre-existing state.
    • Temporary port-forwards and test resources were cleaned.

Detailed test-level evidence is produced by tests/e2e/run.py and the deployment validation commands documented in the repository.

Comment thread .github/workflows/ci.yml Outdated
Comment thread builder/config/adx-standalone.yaml
Comment thread builder/scripts/akernel-entrypoint.sh Outdated
Comment thread builder/scripts/ensure-adx-certs.sh Outdated
Comment thread builder/scripts/fetch_adx_release.py Outdated
Comment thread deploy/akernel/charts/core/templates/etcd/etcd_service.yaml Outdated
Comment thread deploy/akernel/charts/core/templates/frontend/akernel_frontend.yaml Outdated
Comment thread deploy/standalone/README.md Outdated
Comment thread sdk/python/akernel_sdk/_backends/openyuanrong_sandbox.py Outdated
Comment thread README.md Outdated

@WenYuLuo WenYuLuo left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

request change

Comment thread builder/node.Dockerfile Outdated
Comment thread builder/runtime.Dockerfile Outdated

@WenYuLuo WenYuLuo left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

request change

@WenYuLuo
WenYuLuo force-pushed the feat/adx-backend branch 10 times, most recently from 78156e9 to a0842b4 Compare September 29, 2026 02:50
Signed-off-by: robbluo <luo1442@gmail.com>
@WenYuLuo
WenYuLuo force-pushed the feat/adx-backend branch 2 times, most recently from b2fb522 to 7a5626f Compare September 29, 2026 03:34
Signed-off-by: robbluo <luo1442@gmail.com>
Signed-off-by: robbluo <luo1442@gmail.com>
Signed-off-by: robbluo <luo1442@gmail.com>
Signed-off-by: robbluo <luo1442@gmail.com>
Signed-off-by: robbluo <luo1442@gmail.com>
Expose the combined ADX ingress/API deployment through an opt-in LoadBalancer while preserving the separate control and data listener ports.

Signed-off-by: robbluo <luo1442@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant