Skip to content

e2e: guard pod DNS on IPv6-only kind clusters - #10

Draft
ygao-g wants to merge 2 commits into
e2e-ipv6-dns-guard-basefrom
e2e-ipv6-dns-guard
Draft

ygao-g wants to merge 2 commits into
e2e-ipv6-dns-guard-basefrom
e2e-ipv6-dns-guard

Conversation

@ygao-g

@ygao-g ygao-g commented Aug 27, 2026

Copy link
Copy Markdown
Owner

On an IPv6-only kind cluster CoreDNS inherits the node's IPv4 resolver and nothing resolves from inside a pod, so no actor boots and every suite goes red at once without naming the cause. hack/create-kind-cluster.sh repoints CoreDNS at an IPv6 upstream; this asserts the cluster under test actually got that treatment, and names DNS as the reason when it did not.

It replaces the in-script probe removed from agent-substrate#958, and skips unless the cluster is IPv6-only, so it needs an IPv6-only lane (agent-substrate#939) before it executes anywhere. Deliberately a bare pod rather than an Actor: atenet-egress does not go Ready on IPv6-only for an unrelated Envoy bind, which would make an Actor-based assertion a standing red rather than a regression guard.

🤖 Generated with Claude Code

ygao-g added 2 commits August 27, 2026 07:54
Both CI axes are single-family and which one a suite lands on is not fixed,
so a test that only makes sense on one of them has no way to tell.
ClusterIPFamilies reads a node's podCIDRs and returns the set it finds.

First of two commits adding an IPv6-only DNS guard.
kind's DNS translation is IPv4-only: CoreDNS inherits the node's IPv4
resolver, which no pod on an IPv6-only cluster can reach, so nothing
resolves and no actor boots. Every suite then goes red at once and not one
of them names the cause. A busybox pod now looks up an external AAAA and
fails with that diagnosis instead.

It skips unless the cluster is IPv6-only, and probes a bare pod rather than
an Actor: atenet-egress does not go Ready on IPv6-only, for an unrelated
Envoy bind, so an Actor-based assertion would be a standing red.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant