egress: add the egress demo and e2e coverage

demos/egress is a small Actor that fetches a URL it is given and echoes the
upstream status and body back, which makes the egress path observable from
outside the sandbox. hack/install-demo-egress.sh registers it as a
--deploy-demo-egress fixture and hack/verify-egress-demo.sh drives it and
checks the atenet-egress logs for the corresponding authorized CONNECT.

TestActorEgress in the networking suite covers the same path automatically:
it creates an Actor from the demo template, POSTs a fetch request through
atenet-router, and asserts 200. The suite's actor helper is parameterised by
template so the ingress test keeps using the counter fixture.
This commit is contained in:
Lior Lieberman
2026-08-10 23:28:07 -07:00
committed by Bowei Du
parent dd764c1e7c
commit 2f05a92f59
20 changed files with 1017 additions and 107 deletions
+4
View File
@@ -96,6 +96,10 @@ jobs:
run: hack/run-microvm-demo-kind.sh --ateapi-client-auth=${{ matrix.ateapi-client-auth }}
- name: Deploy gVisor counter demo
run: hack/install-ate-kind.sh --deploy-demo-counter
- name: Deploy egress demo
# TestActorEgress in the networking suite builds its Actor from the
# ate-demo-egress/egress ActorTemplate, so the fixture has to exist before.
run: hack/install-ate-kind.sh --deploy-demo-egress
- name: Wait for micro-VM golden snapshot
run: |
kubectl --context kind-kind wait --for=condition=Ready \