mirror of
https://github.com/agent-substrate/substrate.git
synced 2026-10-02 03:24:42 +08:00
Run agentgateway data plane tests as a part of substrate CI (non-blocking to start so we can confirm it's not flaky). Also, change the `--atenet-router` flag to `--atenet-dataplane` to make it clearer that the flag controls ingress and egress. I've run the e2es locally across gVisor and microVM plus the MITM variants for both. The only skip we do for agentgateway is `TestIngressProtocolDowngrade` because 1. the behavior its testing only exists on the non-CONNECT atunnel ingress path and agentgateway only sends CONNECT to atunnel and 2. I'm not sure that we want this to be a part of the contract that substrate is bound by (e.g. do we really want to commit to atunnel always parsing HTTP?). My goal with getting both dataplanes into CI is to start taking steps to codify the proxy (router + egress PEP) contract for substrate. The telemetry they emit, atunnel expectations, etc. are all important contracts to explicitly call out so that they don't become too coupled to a single dataplane implementation. > It's a good idea to open an issue first for discussion. - [X] Tests pass - [X] Appropriate changes to documentation are included in the PR --------- Signed-off-by: Keith Mattix II <keithmattix2@gmail.com>
51 lines
1.7 KiB
Go
51 lines
1.7 KiB
Go
// Copyright 2026 Google LLC
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
package e2e
|
|
|
|
import (
|
|
"net/http"
|
|
"testing"
|
|
)
|
|
|
|
func TestAtenetDataplaneEgressPolicyDenial(t *testing.T) {
|
|
t.Run("envoy", func(t *testing.T) {
|
|
t.Setenv(AtenetDataplaneEnv, "")
|
|
if !CurrentAtenetDataplane().IsEgressPolicyDenied(http.StatusBadGateway, "request failed") {
|
|
t.Error("Envoy CONNECT refusal was not recognized as an egress-policy denial")
|
|
}
|
|
})
|
|
t.Run("agentgateway", func(t *testing.T) {
|
|
t.Setenv(AtenetDataplaneEnv, "agentgateway")
|
|
if !CurrentAtenetDataplane().IsEgressPolicyDenied(http.StatusForbidden, "actor egress policy denied destination") {
|
|
t.Error("AgentGateway direct policy denial was not recognized")
|
|
}
|
|
})
|
|
}
|
|
|
|
func TestAtenetDataplaneTLSPassthroughEgressPolicy(t *testing.T) {
|
|
t.Run("envoy", func(t *testing.T) {
|
|
t.Setenv(AtenetDataplaneEnv, "")
|
|
if !CurrentAtenetDataplane().SupportsTLSPassthroughEgressPolicy() {
|
|
t.Error("Envoy TLS passthrough egress policy was not supported")
|
|
}
|
|
})
|
|
t.Run("agentgateway", func(t *testing.T) {
|
|
t.Setenv(AtenetDataplaneEnv, "agentgateway")
|
|
if CurrentAtenetDataplane().SupportsTLSPassthroughEgressPolicy() {
|
|
t.Error("AgentGateway TLS passthrough egress policy unexpectedly reported support")
|
|
}
|
|
})
|
|
}
|