@@ -87,10 +87,13 @@ func (t *Tester) setSkipRegexFlag() error {
8787 skipRegex += "|should.check.kube-proxy.urls"
8888
8989 if k8sVersion .Minor < 38 {
90- // This seems to be specific to the kube-proxy replacement
90+ // Cilium fails the externalTrafficPolicy=Local sig-network tests: the client source IP is
91+ // SNATed to a pod IP instead of being preserved (long-standing, every build in the retention
92+ // window). Tracked in https://github.com/cilium/cilium/issues/37613, which Cilium's own CI
93+ // cites to skip the whole externalTrafficPolicy family.
9194 // < 38 so we look at this again
9295 skipRegex += "|Services.should.support.externalTrafficPolicy.Local.for.type.NodePort"
93- // https://github.com/kubernetes/kubernetes/issues/129221
96+ skipRegex += "|Services.should.implement.NodePort.and.HealthCheckNodePort.correctly.when.ExternalTrafficPolicy.changes"
9497 }
9598 } else if networking .KubeRouter != nil {
9699 skipRegex += "|should set TCP CLOSE_WAIT timeout|should check kube-proxy urls"
@@ -105,7 +108,6 @@ func (t *Tester) setSkipRegexFlag() error {
105108 if cluster .Spec .LegacyCloudProvider == "azure" {
106109 // Azure Disk CSI fsgroupchangepolicy tests are flaky due to SCSI device discovery
107110 // latency during rapid attach/detach cycles on VMSS nodes.
108- // See https://github.com/kubernetes/kops/issues/17146
109111 skipRegex += "|fsgroupchangepolicy"
110112 // Skipped upstream in azuredisk-csi-driver external E2E:
111113 // https://github.com/kubernetes-sigs/azuredisk-csi-driver/blob/master/test/external-e2e/run.sh
@@ -120,16 +122,14 @@ func (t *Tester) setSkipRegexFlag() error {
120122 skipRegex += "|should.be.mountable.when.non-attachable"
121123 }
122124
123- // This test fails on RHEL-based distros because they return fully qualified hostnames yet the k8s node names are not fully qualified.
124- // Dedicated job testing this: https://testgrid.k8s.io/kops-misc#kops-aws-k28-hostname-bug123255
125- // ref: https://github.com/kubernetes/kops/issues/16349
126- // ref: https://github.com/kubernetes/kubernetes/issues/123255
127- // ref: https://github.com/kubernetes/kubernetes/issues/121018
128- // ref: https://github.com/kubernetes/kubernetes/pull/126896
129- // < 38 so we look at this again
130- if k8sVersion .Minor < 38 {
125+ if k8sVersion .Minor < 37 {
126+ // Services.should.function.for.service.endpoints.using.hostNetwork fails only on distros that
127+ // return fully qualified hostnames (e.g. RHEL) where the k8s node name is not fully qualified;
128+ // it already passes where the system hostname matches the node name. Fixed in k8s 1.37 by
129+ // kubernetes/kubernetes#139819 (compares spec.nodeName instead of os.Hostname()); the
130+ // dedicated reproduction jobs have been removed.
131+ // refs: https://github.com/kubernetes/kops/issues/16349, https://github.com/kubernetes/kubernetes/issues/123255
131132 skipRegex += "|Services.should.function.for.service.endpoints.using.hostNetwork"
132- skipRegex += "|Services.should.implement.NodePort.and.HealthCheckNodePort.correctly.when.ExternalTrafficPolicy.changes"
133133 }
134134
135135 for _ , subnet := range cluster .Spec .Subnets {
0 commit comments