Skip to content

e2e: add test for egress credential injection cujs - #1795

Merged
Bowei Du (bowei) merged 4 commits into
agent-substrate:mainfrom
yufan-su:e2e-cred-injection
Sep 29, 2026
Merged

Bowei Du (bowei) merged 4 commits into
agent-substrate:mainfrom
yufan-su:e2e-cred-injection

Conversation

@yufan-su

Copy link
Copy Markdown
Collaborator

e2e: add e2e for egress credential injection

Adds the egresscredinject e2e suite: an actor fetches https://httpbin.org/headers
through the sdsmint MITM gateway, and the echoed response proves the injected
Authorization header actually reached the upstream.

What it asserts

  • Injected: echoed headers contain Authorization: Bearer <token>.
  • Overwritten: an actor-pre-seeded Authorization is replaced by the injected one.
  • Cleartext skip: plain-HTTP fetch passes through with no Authorization.
  • Fail closed: nonexistent secret → 403, unserved provider → 500,
    unauthorized namespace → 403.

Additional changes

  • Probe /fetch returns the response body, accepts header=<name>:<value>
    params, and no longer follows redirects (a cross-scheme redirect would hop
    between the cleartext and TLS legs). Covered by unit tests; egressmitm rerun green.

  • New e2e.EgressInjectHeader policy helper.

  • New e2e.DeployCredentialProvider + fixtures/credinject: deploys the real
    provider manifest with a test Secret and namespace-policy ConfigMap, restarts
    the provider so it picks the policy up, cleans up on test end.

  • CI: new envoy-lane steps after the MITM lanes, gated on E2E_EGRESS_CREDINJECT=1.

  • Tests pass

  • Appropriate changes to documentation are included in the PR

@yufan-su

Copy link
Copy Markdown
Collaborator Author

Bowei Du (@bowei) PR is updated according to your comments offline.

Comment thread internal/e2e/fixtures/probe/main.go Outdated
Comment thread internal/e2e/credprovider.go Outdated
Comment thread internal/e2e/suites/egresscredinject/egresscredinject_test.go
Comment thread internal/e2e/suites/egresscredinject/egresscredinject_test.go Outdated
Comment thread internal/e2e/suites/egresscredinject/egresscredinject_test.go
Comment thread internal/e2e/suites/egresscredinject/egresscredinject_test.go Outdated
Comment thread internal/e2e/credprovider.go
@bowei
Bowei Du (bowei) added this pull request to the merge queue Sep 29, 2026
Merged via the queue into agent-substrate:main with commit 4f9c293 Sep 29, 2026
10 checks passed
@bowei Bowei Du (bowei) added area/security Security related issue/pr kind/feature An enhancement / feature request or implementation labels Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/network area/security Security related issue/pr area/tests Enhancing / fixing test coverage. kind/feature An enhancement / feature request or implementation

Development

Successfully merging this pull request may close these issues.

3 participants