Skip to content

build: agent-sandbox at upstream main; docs: the warm-candidate grace flag, measured - #84

Merged
CMGS merged 2 commits into
masterfrom
build/agent-sandbox-main
Oct 5, 2026
Merged

CMGS merged 2 commits into
masterfrom
build/agent-sandbox-main

Conversation

@CMGS

@CMGS CMGS commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

What

  • go.mod: sigs.k8s.io/agent-sandbox from ce66bdc to upstream main at fa39d57 (76 commits). In the two API packages this repository imports (api/v1beta1, extensions/api/v1beta1) the change is one new constant, SandboxReasonReconcilerError, plus comment and marker edits. No code here changes.
  • docs/performance.md: the claim controller's 2 s wait for a warm Sandbox's Pod IP is a flag upstream now, --sandbox-claim-warm-candidate-grace-period (agent-sandbox PR 1758, from our issue 1745; on main, in no release up to v1.0.5). The section gains the measurement below and the guidance that follows from it: keep the default.
  • docs/configuration.md, README.md: upstream install lines move from v1.0.3 to v1.0.5, the latest release; the flag is named with its default and release status.

Measurement

Two 384-core hosts, one virtual node each, 150 warm microVMs per node, sandboxd v0.1.15, vk-sandbox v0.1.5. A SandboxWarmPool of 40, then 200 SandboxClaims at create parallelism 20, timed from create to Ready. 14 arms, interleaved, every arm at least twice; 200/200 claims Ready in each.

vk-sandbox pod queues controller, grace claim → Ready p50 / p95 / max Sandboxes the claims created
10/s (library default) v1.0.5, 2 s 0.43–0.52 / 8.5–8.6 / 9.1–9.2 s 123–136 of 200
10/s (library default) fa39d57, 2 s 0.49–0.59 / 8.1–8.7 / 8.9–9.6 s 122–132 of 200
10/s (library default) fa39d57, 10 s 0.51–0.52 / 7.5–8.0 / 9.7 s 105–107 of 200
client budget (200/s) v1.0.5, 2 s 0.48 / 0.85–0.91 / 0.94–0.99 s 74–87 of 200
client budget (200/s) fa39d57, 2 s 0.41–0.46 / 0.83–0.89 / 0.85–0.94 s 82–89 of 200
client budget (200/s) fa39d57, 10 s 0.47 / 0.81–0.86 / 0.85–0.87 s 76–83 of 200
  • A longer grace does not move the latency on either node-side setting. It turns some fallbacks into adoptions; both paths wait in the same Pod queue on the node, and sandboxd gives either one a warm microVM.
  • Most claims that create their own Sandbox do so because the pool holds no member at that moment. Upstream creates at once in that case; the grace covers only candidates that exist without a Pod IP. At 10 s no claim outlived the grace, and 76–107 of 200 still created their own.
  • v1.0.5 behaves like main at the default, on both settings.

Not measured: the L3 path. Its two CRDs differ between v1.0.3 and v1.0.5 by one printer column.

Gates

GOWORK=off: go mod tidy (no further diff), go build and go vet on linux and darwin, make generate (no diff), asl on both GOOS, make lint (10 of 10 runs 0 issues.), make fmt-check, helm lint, go test -race -count=1 ./... — all clean.

Hot-path cost: none, no code changes.

CMGS added 2 commits October 5, 2026 13:35
From ce66bdc, 76 commits. In the two API packages this repository imports, the change is one new constant and comment or marker edits.
… at v1.0.5

Upstream made the claim controller's 2 s wait for a warm Sandbox's Pod IP a flag (agent-sandbox PR 1758, from our issue 1745). Measured on the two-node testbed at 2 s and 10 s, slow and fast node side: latency does not move, so the docs name the flag and keep the default. v1.0.5, the latest release, ran alongside main and behaves the same; the install lines move to it.
@CMGS
CMGS merged commit f857b04 into master Oct 5, 2026
2 checks passed
@CMGS
CMGS deleted the build/agent-sandbox-main branch October 5, 2026 05:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant