Conversation
The e2e data plane ran Envoy contrib-v1.37.1 and a multi-arch WAF build that production never shipped, so e2e did not test the proxy and filter the edge actually runs. Pin both to the production edge images. Key changes: - Envoy proxy contrib-v1.37.1 to contrib-v1.39.1 in the e2e EnvoyProxy - Coraza WAF v1.3.0-multiarch.1 to v2.0.4 in the EnvoyProxy and Taskfile - Record the Envoy pin and the new WAF pin in the e2e version-pin table - Bump the dev environment to the same Envoy and WAF images v2.0.4 is amd64-only, so arm64 dev hosts now need CORAZA_DISABLED=true.
kevwilliams
approved these changes
Sep 25, 2026
kevwilliams
left a comment
Contributor
There was a problem hiding this comment.
Moves the e2e and dev Envoy proxy and Coraza WAF pins to the exact images production runs (contrib-v1.39.1, WAF v2.0.4), replacing the older multi-arch WAF build that never shipped to production. Discloses the trade-off: the production WAF image is amd64-only, so arm64 dev hosts run with CORAZA_DISABLED=true, trading local WAF coverage for exact CI parity with production. Version-pin table updated to match. CI green.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
End-to-end tests ran an older Envoy proxy and a WAF build that production never shipped, so a green run said nothing about the proxy and filter the edge actually serves traffic with.
The test and dev environments now run the production edge Envoy proxy, contrib-v1.39.1, and the production Coraza WAF, v2.0.4, and the version-pin table records both.
The production WAF image is amd64-only, so arm64 dev hosts must run with the WAF disabled, which trades local WAF coverage for exact production parity in CI.
Test plan
Related to datum-cloud/infra#6069