Files
substrate/demos
yufan-su 62dbb86718 e2e: cover egress on grpc requests and bidi streaming (#1119)
Add an e2e test to cover egress on sending grpc requests and bidi
streaming in it.

What's here

- `internal/proto/grpcechopb` — a small Echo service with one method per
streaming shape: unary Echo, server-streaming EchoStream, bidirectional
EchoBidi. Generated files checked in, per the convention in the
neighbouring proto packages.
- `internal/e2e/fixtures/grpcecho` — the origin: a cleartext-HTTP/2
server, no TLS anywhere, with the standard health service so the pod can
use a grpc readinessProbe and nothing between the actor and the origin
parses HTTP. Pod + Service template, deployed per test into the suite's
namespace.
- `demos/egress` — the actor gains POST /grpc, which dials the target
and runs whichever RPCs the request asks for. It dials per request and
closes with it: the actor is checkpointed and restored, and an HTTP/2
connection opened before a snapshot does not survive one. The gRPC
status comes back as a string rather than being flattened into the HTTP
status, since that status is the trailer assertion.
- `internal/e2e/suites/networking/grpcegress_test.go` —
TestActorEgressGRPC drives all three shapes through nftables REDIRECT →
atunnel → atenet-egress → origin, then asserts the gateway's access log
recorded the CONNECT for that actor's certificate. Without that last
check everything above would also pass on masqueraded traffic that never
reached the gateway.

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR
2026-08-24 16:24:24 -04:00
..