Files
substrate/internal/e2e/atenet_dataplane_test.go
Keith Mattix II abd45ad081 Add agentgateway to CI & rename dataplane flag (#1598)
Run agentgateway data plane tests as a part of substrate CI
(non-blocking to start so we can confirm it's not flaky). Also, change
the `--atenet-router` flag to `--atenet-dataplane` to make it clearer
that the flag controls ingress and egress.

I've run the e2es locally across gVisor and microVM plus the MITM
variants for both. The only skip we do for agentgateway is
`TestIngressProtocolDowngrade` because 1. the behavior its testing only
exists on the non-CONNECT atunnel ingress path and agentgateway only
sends CONNECT to atunnel and 2. I'm not sure that we want this to be a
part of the contract that substrate is bound by (e.g. do we really want
to commit to atunnel always parsing HTTP?).

My goal with getting both dataplanes into CI is to start taking steps to
codify the proxy (router + egress PEP) contract for substrate. The
telemetry they emit, atunnel expectations, etc. are all important
contracts to explicitly call out so that they don't become too coupled
to a single dataplane implementation.

> It's a good idea to open an issue first for discussion.

- [X] Tests pass
- [X] Appropriate changes to documentation are included in the PR

---------

Signed-off-by: Keith Mattix II <keithmattix2@gmail.com>
2026-09-15 08:47:41 -07:00

51 lines
1.7 KiB
Go

// Copyright 2026 Google LLC
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package e2e
import (
"net/http"
"testing"
)
func TestAtenetDataplaneEgressPolicyDenial(t *testing.T) {
t.Run("envoy", func(t *testing.T) {
t.Setenv(AtenetDataplaneEnv, "")
if !CurrentAtenetDataplane().IsEgressPolicyDenied(http.StatusBadGateway, "request failed") {
t.Error("Envoy CONNECT refusal was not recognized as an egress-policy denial")
}
})
t.Run("agentgateway", func(t *testing.T) {
t.Setenv(AtenetDataplaneEnv, "agentgateway")
if !CurrentAtenetDataplane().IsEgressPolicyDenied(http.StatusForbidden, "actor egress policy denied destination") {
t.Error("AgentGateway direct policy denial was not recognized")
}
})
}
func TestAtenetDataplaneTLSPassthroughEgressPolicy(t *testing.T) {
t.Run("envoy", func(t *testing.T) {
t.Setenv(AtenetDataplaneEnv, "")
if !CurrentAtenetDataplane().SupportsTLSPassthroughEgressPolicy() {
t.Error("Envoy TLS passthrough egress policy was not supported")
}
})
t.Run("agentgateway", func(t *testing.T) {
t.Setenv(AtenetDataplaneEnv, "agentgateway")
if CurrentAtenetDataplane().SupportsTLSPassthroughEgressPolicy() {
t.Error("AgentGateway TLS passthrough egress policy unexpectedly reported support")
}
})
}