File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -103,12 +103,15 @@ func (t *Tester) setSkipRegexFlag() error {
103103 // test requires externalTrafficPolicy=Local source-IP preservation, which is broken on these
104104 // CNIs: the client IP is SNATed to a pod IP instead of being preserved (kube-router instead
105105 // times out reaching the local endpoint). Confirmed failing on cilium, flannel, kopeio and
106- // kube-router on all clouds, and on calico on GCE (calico preserves the source IP on AWS).
107- // amazon-vpc and kindnet preserve it and keep running the test.
106+ // kube-router on all clouds, and on calico on GCE and Azure, where the underlay cannot route
107+ // the pod CIDR so calico encapsulates inter-node pod traffic (IPIP tunl0 on GCE, VXLAN
108+ // vxlan.calico on Azure) and the masquerade rewrites the source to the node's tunnel address.
109+ // Calico preserves the source IP only on AWS, where kOps disables the source/dest check and
110+ // routes pod traffic natively. amazon-vpc and kindnet preserve it and keep running the test.
108111 // < 38 so we look at this again
109112 if k8sVersion .Minor < 38 &&
110113 (networking .Cilium != nil || networking .Flannel != nil || networking .Kopeio != nil || networking .KubeRouter != nil ||
111- (networking .Calico != nil && cluster .Spec .LegacyCloudProvider == "gce" )) {
114+ (networking .Calico != nil && ( cluster .Spec .LegacyCloudProvider == "gce" || cluster . Spec . LegacyCloudProvider == "azure" ) )) {
112115 skipRegex += "|Services.should.implement.NodePort.and.HealthCheckNodePort.correctly.when.ExternalTrafficPolicy.changes"
113116 }
114117
You can’t perform that action at this time.
0 commit comments