Skip to content

Support unix domain sockets - #784

Open
christoph-hamm wants to merge 35 commits into
mainfrom
780_support-unix-domain-sockets
Open

christoph-hamm wants to merge 35 commits into
mainfrom
780_support-unix-domain-sockets

Conversation

@christoph-hamm

@christoph-hamm christoph-hamm commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

Issues: #780

Definition of Done

The PR shall be merged only if all items mentioned in CONTRIBUTING.md have been followed. In case an item is not applicable as described, please provide a short explanation in the description.

ToDo

  • implement UDS in server
  • implement UDS in agent
  • implement UDS in CLI
  • adapt devcontainer
  • adapt installation script
  • adapt debian package
  • check documentation
  • get stests to work again in devcontainer
  • adapt AUR packages

@christoph-hamm
christoph-hamm force-pushed the 780_support-unix-domain-sockets branch from d1adf6c to b580024 Compare August 27, 2026 08:23
@christoph-hamm christoph-hamm added the enhancement New feature or request. Issue will appear in the change log "Features" label Aug 27, 2026
@christoph-hamm

Copy link
Copy Markdown
Contributor Author

The domains sockets have been added to the ank-server, ank-agent and ank. The devcontainer config, debian package and the install script have been updated as well. All three are working. Only for devcontainer the stests are not working at the moment.

I have not checked the documentation yet, if everything is still working. I think we need to mention the new ankaios group, and that you have to be part of that group in order to use the ankaios CLI. We can also remove the warning in the documentation.

@christoph-hamm christoph-hamm linked an issue Aug 27, 2026 that may be closed by this pull request
3 tasks
@christoph-hamm
christoph-hamm force-pushed the 780_support-unix-domain-sockets branch from d97f7da to 53f0cad Compare September 24, 2026 13:54
@sonarqubecloud

Copy link
Copy Markdown

@krucod3

krucod3 commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

I'll start with the review here.

Comment thread tools/debian/build_src_pkg.sh Outdated

@krucod3 krucod3 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Initial review done. Configs and documentation are now reviewed. I'll continue with the rest now.

Comment thread agent/config/ank-agent.conf Outdated
Comment thread agent/src/agent_config.rs Outdated

fn validate_socket_configuration(agent_config: &AgentConfig) -> Result<(), String> {
validate_unix_socket_tls_settings(
"agent",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I somehow don't like this string here ...

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

At the end it's mean to reduce code duplications, but the or below is still repeated and we have a freely configurable string as input. The logic in the common function is also not really complex. Maybe just providing common functions is_unix is is_tcp would make more sense.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have removed the the parameter. The call as now using map_err to adding a prefix.

Comment thread agent/config/ank-agent.conf Outdated
# The server url.
# server_url = 'https://127.0.0.1:25551'
# The server endpoint.
address = 'unix:///run/ankaios/server.sock'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why renaming here? A domain socket is still specified by a url which includes also the protocol, in this case "unix://"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changed it back to URL.

Comment thread common/src/config.rs Outdated
Comment on lines +54 to +55
if address.starts_with("https://") || address.starts_with("http://") {
Ok(())

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So if only https:// it's OK?

@christoph-hamm christoph-hamm Oct 7, 2026 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The code is now changed, as the URL is more early put in an enum to distinguish HTTP from UDS. But the logic is still the same, for UDS we check it is not empty, for URL we do not. For UDS the check is primarily there, to check for an absolute path, and returning an error saying it is not absolute for an empty path would be strange, hence the special handling for empty. For HTTP it is as before. If we start checking we could add more and more checks to see it is an valid HTTP URL, and I do not want to start this.

Comment thread agent/src/cli.rs Outdated
)]
/// The server endpoint.
/// Supported values are https://host:port and unix:///path/to/socket.
pub address: Option<String>,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again, I don't understand why we want to change the external interface of the agent. server url is already correct.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is back to server_url.

Comment thread agent/src/main.rs Outdated
Comment on lines +196 to +206
let tls_config = if agent_config.address.starts_with("unix://") {
None
} else {
if let Err(err_message) = TLSConfig::is_config_conflicting(
agent_config.insecure,
&agent_config.ca_pem_content,
&agent_config.crt_pem_content,
&agent_config.key_pem_content,
) {
log::warn!("{err_message}");
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a bit strange now. We already did some checks about TLS, insecure and connection type, and now we start to create the TLS config and ignore the uds connections ...
I have not looked in detail and there are some differences between server and agent/ank handling, but maybe there is a better way to organize the config handling.

@christoph-hamm christoph-hamm Oct 7, 2026 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We checked if the config is valid before, and now we only create the tls config if it is needed. Maybe at the initial check we could create some enum structure which only allow valid configuration and which might remove some checks here, or something similar with traits. I think it is OK as it is and would not change it.

Comment thread doc/docs/reference/config-files.md Outdated
# If set to 'true' and the certificates are not provided, then the server shall not use TLS.
insecure = false
# This option must not be used with 'unix://' addresses.
# insecure = true

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we should leave the default to false also in the example.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Set it to false again.

Comment on lines +86 to +87
If no `address` is configured and no configuration file is used, the Ankaios server defaults to
the TCP address `127.0.0.1:25551`.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So if nothing is configured, Ankaios does not start?
default url is http and insecure is per default false. No default tls config => fail to start. Maybe default should be uds.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Below there is another paragraph stating that the default is the domain socket:
https://github.com/eclipse-ankaios/ankaios/pull/784/changes#diff-f37a7d24bc9ebf61ff0c5e3165666b5590ba702a6ad912760833cfd3024f855eR50-R52

Which one is correct?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If you have no configuration files, the default is 127.0.0.1:5551 but as no certificates are provided, it will not start. I was also thinking about changing it to UDS as default, but this would be a breaking change. E.g. a user has a configuration files only configuring the certificate, the server would now start listening on the default https://127.0.01:5551. If we would now make UDS the default, it would not listen to localhost anymore or crash for wrong configuration (depending on whether we are changing this or not).

The thing below ist about the default installation methods. Here some configuration files are installed as well, which default to UDS.

Comment thread common/src/config.rs Outdated
}

pub fn validate_server_address_format(address: &str) -> Result<(), String> {
if let Some(path) = address.strip_prefix("unix://") {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please introduce constants for the protocol identifiers.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

Comment thread doc/docs/usage/network-setup.md Outdated

```toml
address = 'https://127.0.0.1:25551'
insecure = false

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We don't need the false here as it is default.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

removed

@krucod3 krucod3 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review the rest without tools folder. Will review this one after all changes there are pushed.

Comment thread grpc/doc/swdesign/README.md Outdated
- itest

#### gRPC Server supports unix domain socket endpoints
`swdd~grpc-server-supports-unix-domain-socket-endpoints~1`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

And the client does not need anything?
We should add another req for the client too.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have added an requirements for the client.


Status: approved

The gRPC Server shall support listening for incoming gRPC connections on either a TCP socket endpoint or a Unix domain socket endpoint.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The name is about Unix domain sockets, but the description mentions either TCP or Unix sockets.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated the description.

Comment thread grpc/doc/swdesign/README.md Outdated
The gRPC Server shall support listening for incoming gRPC connections on either a TCP socket endpoint or a Unix domain socket endpoint.

Rationale:
Unix domain sockets allow local communication without exposing a TCP port.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

But requires a socket. That's not a rationale. Suggestion:

Suggested change
Unix domain sockets allow local communication without exposing a TCP port.
Unix domain sockets are faster and allow securing local communication using IAM improving the ease of use.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I took you rational but dropped the "faster" part, as this was not a reason we added them.

Comment thread grpc/src/client.rs Outdated
Comment on lines +71 to +72
fn parse_server_endpoint(
server_address: &String,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I still think calling is url instead of endpoint or address is more precise.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is URL again.

Comment thread grpc/src/client.rs Outdated
Comment on lines +424 to +425
- utest

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could also stest the group setting and the permissions.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could but I am not sure if it is worth it. We have to ensure the test user has supplementary group we can use for the test. We also have to ensure the umask does not produce the wanted file permissions.

I see it like this: we have tested in manually and it works, and I think it is unlikely it is removed or changed accidentally, as we also have utest for this.

let server_config_content = r"#
version = 'v1'
address = 'unix:///tmp/ankaios-server.sock'
ca_pem = '/tmp/.certs/ca.pem'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ca_pem_content is not tested.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added unit test for ca_pem_content.

Comment thread tests/resources/variables.resource Outdated
${AGENT_NAME}= agent_A
${AGENT_2_NAME}= agent_B
${ANKAIOS_TMP_FOLDER}= /tmp/ankaios
${ANKAIOS_SERVER_URL}= unix:///tmp/ankaios.sock

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would go for a more prescriptive name containing UDS or UNIX, etc.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renamed it to ANKAIOS_SERVER_SOCKET_URL.

Comment thread tests/resources/ankaios.resource Outdated
Comment on lines +98 to +100
Set Environment Variable name=ANKSERVER_SERVER_URL value=${ANKAIOS_SERVER_URL}
Set Environment Variable name=ANKAGENT_SERVER_URL value=${ANKAIOS_SERVER_URL}
Set Environment Variable name=ANK_SERVER_URL value=${ANKAIOS_SERVER_URL}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So now the stests could leave the environment changed in case the variables were not set.
I get the intention as they are normally ran by as in the devcontainer and there we have the variable as you are setting it now.

Let's go for this solution for now. If we get into trouble we could think about using configs in the dev environment and unsetting the vars here.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I do not know what you mean here? Is your idea you start a shell, execute the stests and afterwards the environment variables of you shell are different? This will never happen as a child process can not change the environment variables of the parent process.

And the workload "hello3" shall have the execution state "Pending(Initial)" on agent "agent_B"
# Actions
When user triggers "ank -k get agents"
When user triggers "ank get agents"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎆 Yeah! Finally get rid of the -k 👍

@krucod3 krucod3 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes in the tools are now reviewed too and look good 👍

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request. Issue will appear in the change log "Features" ready for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support Unix Domain Sockets

3 participants