Skip to content

chore: Run end-to-end tests on the production edge Envoy and WAF - #501

Open
ecv wants to merge 1 commit into
mainfrom
chore/e2e-envoy-1.39.1
Open

ecv wants to merge 1 commit into
mainfrom
chore/e2e-envoy-1.39.1

Conversation

@ecv

@ecv ecv commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Summary

End-to-end tests ran an older Envoy proxy and a WAF build that production never shipped, so a green run said nothing about the proxy and filter the edge actually serves traffic with.

The test and dev environments now run the production edge Envoy proxy, contrib-v1.39.1, and the production Coraza WAF, v2.0.4, and the version-pin table records both.

The production WAF image is amd64-only, so arm64 dev hosts must run with the WAF disabled, which trades local WAF coverage for exact production parity in CI.

Test plan

  • Single-cluster and federated end-to-end suites pass, WAF scenarios included

Related to datum-cloud/infra#6069

The e2e data plane ran Envoy contrib-v1.37.1 and a multi-arch WAF build
that production never shipped, so e2e did not test the proxy and filter
the edge actually runs. Pin both to the production edge images.

Key changes:
- Envoy proxy contrib-v1.37.1 to contrib-v1.39.1 in the e2e EnvoyProxy
- Coraza WAF v1.3.0-multiarch.1 to v2.0.4 in the EnvoyProxy and Taskfile
- Record the Envoy pin and the new WAF pin in the e2e version-pin table
- Bump the dev environment to the same Envoy and WAF images

v2.0.4 is amd64-only, so arm64 dev hosts now need CORAZA_DISABLED=true.
@ecv
ecv marked this pull request as ready for review September 25, 2026 19:10
@ecv
ecv requested a review from a team as a code owner September 25, 2026 19:10
@ecv
ecv requested a review from scotwells September 25, 2026 19:10

@kevwilliams kevwilliams left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moves the e2e and dev Envoy proxy and Coraza WAF pins to the exact images production runs (contrib-v1.39.1, WAF v2.0.4), replacing the older multi-arch WAF build that never shipped to production. Discloses the trade-off: the production WAF image is amd64-only, so arm64 dev hosts run with CORAZA_DISABLED=true, trading local WAF coverage for exact CI parity with production. Version-pin table updated to match. CI green.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants