Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Bug]: demos/sandbox client fails with missing bearer token on actor resume

Open Beginner friendly
#1,579 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
1/5
Estimated time
Under an hour
Newbie friendliness
85/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
go, grpc

Research direction

Inspect demos/sandbox/client/main.go, especially dialAteAPI() and the ResumeActor call path, then compare with existing uses of internal/ateclient.NewClient in the repo for expected auth setup. Reproduce first with the documented port-forward steps and go run ./demos/sandbox/client --atespace=demo --name=sb1 to confirm the current missing bearer token failure. Completion is when the command resumes the actor without authentication error and no longer hits the unauthenticated RPC result.

Written by the indexing model from the issue text.

Description

area/demos kind/bug
What happened?

Summary

Running demos/sandbox/client fails when invoking ResumeActor against ate-api because the client establishes an unauthenticated gRPC connection without attaching a Bearer token.

Steps to Reproduce

  1. Port-forward the Substrate API server (kubectl port-forward -n ate-system svc/api 8080:443).
  2. Run the sandbox client:
    go run ./demos/sandbox/client --atespace=demo --name=sb1
    

Actual Behavior

2026/09/09 21:51:13 Connecting to ateapi at localhost:8080...
2026/09/09 21:51:13 Resuming actor sb1...
2026/09/09 21:51:13 Failed to resume actor: rpc error: code = Unauthenticated desc = missing bearer token

Root Cause

demos/sandbox/client/main.go uses a custom dialAteAPI() helper that calls grpc.NewClient with TLS but omits PerRPCCredentials (Bearer JWT / ServiceAccount token). As a result, ate-api's auth interceptor rejects the unauthenticated request.

Expected Behavior

The client should authenticate with ate-api using the standard internal/ateclient.NewClient, which automatically:

  • Obtains an ate-client ServiceAccount bearer token via the k8s TokenRequest API (or uses --token-file).
  • Validates the serving certificate against ClusterTrustBundle.
  • Injects bearer credentials into RPC requests.
Steps to Reproduce
  1. Deploy the sandbox demo on an Agent Substrate cluster:
    ./hack/install-ate.sh --deploy-demo-sandbox

  2. Create a sandbox actor:
    kubectl ate create actor sb1 -a ate-demo-sandbox --template sandbox-template

  3. Port-forward the API and router:

       kubectl port-forward -n ate-system svc/atenet-router 8000:80 &
  1. Run the sandbox client:
    go run ./demos/sandbox/client --atespace=ate-demo-sandbox --name=sb1

  2. Error:
    Failed to resume actor: rpc error: code = Unauthenticated desc = missing bearer token

Sandbox Runtime

gVisor (runsc)

Agent Substrate Version / Commit SHA

0b3d2d078

Kubernetes Version & Environment

No response

Host OS & Architecture

No response

Relevant Logs and Diagnostic Output

Additional Context

No response

Confirmation
  • I have searched existing issues and verified that this is not a duplicate.
  • I have verified that this issue occurs on the latest commit on main.
Dominant language
Go
Stars
4k
Forks
473
Avg merge
2d 3h
Merged PRs (30d)
265

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from agent-substrate/substrate

All issues in agent-substrate/substrate

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.