Problem
The chart pins the egress gateway image agentgateway-upstream/agentgateway:2.2.1. With it, an egress policy call whose request never reached its policy service (connection refused, service down) is answered 403 denied, so an agent cannot tell a policy refusal from an outage. agentgateway-upstream v2.2.2 carries the fix that answers such a call 503 unavailable.
Proposed solution
Bump images.agentgateway in charts/substrate/values.yaml from 2.2.1 to the stable 2.2.2. Values only; no template change.
Acceptance criteria
- The chart's default egress gateway image is
gsoci.azurecr.io/giantswarm/agentgateway-upstream/agentgateway:2.2.2, and the chart tests (images_test rejects pre-release tags) pass.
- A Substrate release candidate with the bump deploys, and its egress gateway runs 2.2.2 with the agent and platform end-to-end suites green.
Problem
The chart pins the egress gateway image
agentgateway-upstream/agentgateway:2.2.1. With it, an egress policy call whose request never reached its policy service (connection refused, service down) is answered403 denied, so an agent cannot tell a policy refusal from an outage. agentgateway-upstream v2.2.2 carries the fix that answers such a call503 unavailable.Proposed solution
Bump
images.agentgatewayincharts/substrate/values.yamlfrom 2.2.1 to the stable 2.2.2. Values only; no template change.Acceptance criteria
gsoci.azurecr.io/giantswarm/agentgateway-upstream/agentgateway:2.2.2, and the chart tests (images_test rejects pre-release tags) pass.