Sitelet https://github.com/kubernetes/kops/pull/17962/files
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
76 changes: 25 additions & 51 deletions tests/e2e/scenarios/addon-resource-tracking/run-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -15,58 +15,32 @@
# limitations under the License.

REPO_ROOT=$(git rev-parse --show-toplevel);
TEST_ROOT="${REPO_ROOT}/tests/e2e/scenarios/addon-resource-tracking"

export KOPS_FEATURE_FLAGS="SpecOverrideFlag"
source "${REPO_ROOT}"/tests/e2e/scenarios/lib/common.sh

function haveds() {
local ds=0
kubectl get ds -n kube-system aws-node-termination-handler --show-labels || ds=$?
return $ds
}

# Start a cluster with an old version of channel

export KOPS_BASE_URL
KOPS_BASE_URL="https://artifacts.k8s.io/binaries/kops/1.29.2"
KOPS=$(kops-download-from-base)

# Start with a cluster running nodeTerminationHandler
ARGS="--set=cluster.spec.cloudProvider.aws.nodeTerminationHandler.enabled=true"
ARGS="${ARGS} --set=cluster.spec.cloudProvider.aws.nodeTerminationHandler.enableSQSTerminationDraining=false"

${KUBETEST2} \
--up \
make test-e2e-install

# Download kOps 1.29.2 to create the initial cluster
export KOPS_BASE_URL="https://artifacts.k8s.io/binaries/kops/1.29.2"
KOPS_BIN=$(mktemp -t kops.XXXXXXXXX)
wget -qO "${KOPS_BIN}" "$KOPS_BASE_URL/$(go env GOOS)/$(go env GOARCH)/kops"
chmod +x "${KOPS_BIN}"

# Create cluster with nodeTerminationHandler enabled (DaemonSet mode)
CREATE_ARGS="--networking calico"
CREATE_ARGS="${CREATE_ARGS} --set=cluster.spec.cloudProvider.aws.nodeTerminationHandler.enabled=true"
CREATE_ARGS="${CREATE_ARGS} --set=cluster.spec.cloudProvider.aws.nodeTerminationHandler.enableSQSTerminationDraining=false"

KUBETEST2_ARGS=()
KUBETEST2_ARGS+=("-v=2")
KUBETEST2_ARGS+=("--env=KOPS_FEATURE_FLAGS=${KOPS_FEATURE_FLAGS}")
KUBETEST2_ARGS+=("--kops-binary-path=${KOPS_BIN}")

kubetest2 kops \
--up --down \
"${KUBETEST2_ARGS[@]}" \
--cloud-provider=aws \
--create-args="${CREATE_ARGS}" \
--kubernetes-version="1.29.8" \
--kops-binary-path="${KOPS}" \
--create-args="$ARGS"


if ! haveds; then
echo "Expected aws-node-termination-handler to exist"
exit 1
fi

# Upgrade to a version that should adopt existing resources and apply the change below
kops-acquire-latest

cp "${KOPS}" "${WORKSPACE}/kops"

# Switch to queue mode. This should remove the DS and install a Deployment instead
kops edit cluster "${CLUSTER_NAME}" "--set=cluster.spec.cloudProvider.aws.nodeTerminationHandler.enableSQSTerminationDraining=true"

# allow downgrade is a bug where the version written to VFS is not the same as the running version.
kops update cluster --allow-kops-downgrade
kops update cluster --yes --allow-kops-downgrade

# Rolling-upgrade is needed so we get the new channels binary that supports prune
kops rolling-update cluster --instance-group-roles=master --yes

# just make sure pods are ready
kops validate cluster --wait=5m

# We should no longer have a daemonset called aws-node-termination-handler
if haveds; then
echo "Expected aws-node-termination-handler to have been pruned"
exit 1
fi
--test=exec -- "${TEST_ROOT}/test.sh"
61 changes: 61 additions & 0 deletions tests/e2e/scenarios/addon-resource-tracking/test.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
#!/usr/bin/env bash

# Copyright 2026 The Kubernetes Authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

set -o errexit
set -o nounset
set -o pipefail

function haveds() {
local ds=0
kubectl get ds -n kube-system aws-node-termination-handler --show-labels || ds=$?
return $ds
}

# Verify we start with a DaemonSet
if ! haveds; then
echo "Expected aws-node-termination-handler to exist"
exit 1
fi

# Download latest kOps to upgrade the cluster
KOPS_BASE_URL="$(curl -s https://storage.googleapis.com/k8s-staging-kops/kops/releases/markers/master/latest-ci-updown-green.txt)"
KOPS=$(mktemp -t kops.XXXXXXXXX)
wget -qO "${KOPS}" "$KOPS_BASE_URL/$(go env GOOS)/$(go env GOARCH)/kops"
chmod +x "${KOPS}"

# Get cluster name from current context
CLUSTER_NAME=$(kubectl config view --minify -o jsonpath='{.clusters[0].name}')

# Switch to queue mode. This should remove the DS and install a Deployment instead
"${KOPS}" edit cluster "${CLUSTER_NAME}" "--set=cluster.spec.cloudProvider.aws.nodeTerminationHandler.enableSQSTerminationDraining=true"

# allow downgrade is a bug where the version written to VFS is not the same as the running version.
"${KOPS}" update cluster --allow-kops-downgrade
"${KOPS}" update cluster --yes --allow-kops-downgrade

# Rolling-upgrade is needed so we get the new channels binary that supports prune
"${KOPS}" rolling-update cluster --instance-group-roles=master --yes

# just make sure pods are ready
"${KOPS}" validate cluster --wait=5m

# We should no longer have a daemonset called aws-node-termination-handler
if haveds; then
echo "Expected aws-node-termination-handler to have been pruned"
exit 1
fi

echo "Test passed: aws-node-termination-handler DaemonSet was successfully pruned after upgrade"
47 changes: 22 additions & 25 deletions tests/e2e/scenarios/aws-ebs-csi/run-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -15,33 +15,30 @@
# limitations under the License.

REPO_ROOT=$(git rev-parse --show-toplevel);
source "${REPO_ROOT}"/tests/e2e/scenarios/lib/common.sh
TEST_ROOT="${REPO_ROOT}/tests/e2e/scenarios/aws-ebs-csi"

kops-acquire-latest
make test-e2e-install

OVERRIDES="${OVERRIDES-} --set=cluster.spec.cloudProvider.aws.ebsCSIDriver.enabled=true"
OVERRIDES="$OVERRIDES --set=cluster.spec.snapshotController.enabled=true"
OVERRIDES="$OVERRIDES --set=cluster.spec.certManager.enabled=true"
OVERRIDES="$OVERRIDES --control-plane-size=t3.medium --node-size=c5.large"
KUBETEST2_ARGS=()
KUBETEST2_ARGS+=("-v=2")

kops-up

ZONE=$(${KOPS} get ig -o json | jq -r '[.[] | select(.spec.role=="Node") | .spec.subnets[0]][0]')
REPORT_DIR="${ARTIFACTS:-$(pwd)/_artifacts}/aws-ebs-csi-driver/"

# shellcheck disable=SC2164
cd "$(mktemp -dt kops.XXXXXXXXX)"
go get github.com/onsi/ginkgo/ginkgo

CSI_VERSION=$(kubectl get deployment -n kube-system ebs-csi-controller -o jsonpath='{.spec.template.spec.containers[?(@.name=="ebs-plugin")].image}' | cut -d':' -f2-)
CLONE_ARGS=
if [ -n "$CSI_VERSION" ]; then
CLONE_ARGS="-b ${CSI_VERSION}"
if [[ "${JOB_TYPE}" == "presubmit" && "${REPO_OWNER}/${REPO_NAME}" == "kubernetes/kops" ]]; then
KUBETEST2_ARGS+=("--build")
KUBETEST2_ARGS+=("--kops-binary-path=${GOPATH}/src/k8s.io/kops/.build/dist/linux/$(go env GOARCH)/kops")
else
KUBETEST2_ARGS+=("--kops-version-marker=${KOPS_VERSION_MARKER:-https://storage.googleapis.com/k8s-staging-kops/kops/releases/markers/master/latest-ci.txt}")
fi
# shellcheck disable=SC2086
git clone ${CLONE_ARGS} https://github.com/kubernetes-sigs/aws-ebs-csi-driver.git .

# shellcheck disable=SC2164
cd tests/e2e-kubernetes/

ginkgo --nodes=25 ./... -- -cluster-tag="${CLUSTER_NAME}" -ginkgo.skip="\[Disruptive\]" -report-dir="${REPORT_DIR}" -gce-zone="${ZONE}"
CREATE_ARGS="--networking calico"
CREATE_ARGS="${CREATE_ARGS} --set=cluster.spec.cloudProvider.aws.ebsCSIDriver.enabled=true"
CREATE_ARGS="${CREATE_ARGS} --set=cluster.spec.snapshotController.enabled=true"
CREATE_ARGS="${CREATE_ARGS} --set=cluster.spec.certManager.enabled=true"
CREATE_ARGS="${CREATE_ARGS} --control-plane-size=t3.medium --node-size=c5.large"

kubetest2 kops \
--up --down \
"${KUBETEST2_ARGS[@]}" \
--cloud-provider=aws \
--create-args="${CREATE_ARGS}" \
--kubernetes-version="https://dl.k8s.io/release/stable.txt" \
--test=exec -- "${TEST_ROOT}/test.sh"
46 changes: 46 additions & 0 deletions tests/e2e/scenarios/aws-ebs-csi/test.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
#!/usr/bin/env bash

# Copyright 2026 The Kubernetes Authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

set -o errexit
set -o nounset
set -o pipefail

# Get the cluster name from the KUBECONFIG context
CLUSTER_NAME=$(kubectl config view --minify -o jsonpath='{.clusters[0].name}')

# Get the zone from an instance group
ZONE=$(kubectl get nodes -o jsonpath='{.items[0].metadata.labels.topology\.kubernetes\.io/zone}')

REPORT_DIR="${ARTIFACTS:-$(pwd)/_artifacts}/aws-ebs-csi-driver/"
mkdir -p "${REPORT_DIR}"

# Clone the aws-ebs-csi-driver repo at the version deployed in the cluster
CSI_VERSION=$(kubectl get deployment -n kube-system ebs-csi-controller -o jsonpath='{.spec.template.spec.containers[?(@.name=="ebs-plugin")].image}' | cut -d':' -f2-)
TEMPDIR=$(mktemp -dt kops.XXXXXXXXX)
cd "${TEMPDIR}"

go install github.com/onsi/ginkgo/v2/ginkgo@latest

CLONE_ARGS=
if [ -n "$CSI_VERSION" ]; then
CLONE_ARGS="-b ${CSI_VERSION}"
fi
# shellcheck disable=SC2086
git clone ${CLONE_ARGS} https://github.com/kubernetes-sigs/aws-ebs-csi-driver.git .

cd tests/e2e-kubernetes/

ginkgo --nodes=25 ./... -- -cluster-tag="${CLUSTER_NAME}" -ginkgo.skip="\[Disruptive\]" -report-dir="${REPORT_DIR}" -gce-zone="${ZONE}"
48 changes: 26 additions & 22 deletions tests/e2e/scenarios/cilium-connectivity-test/run-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -15,32 +15,36 @@
# limitations under the License.

REPO_ROOT=$(git rev-parse --show-toplevel);
source "${REPO_ROOT}"/tests/e2e/scenarios/lib/common.sh
TEST_ROOT="${REPO_ROOT}/tests/e2e/scenarios/cilium-connectivity-test"

export KOPS_BASE_URL
KOPS_BASE_URL="$(curl -s https://storage.googleapis.com/k8s-staging-kops/kops/releases/markers/master/latest-ci-updown-green.txt)"
KOPS=$(kops-download-from-base)
make test-e2e-install

ARGS="--set=cluster.spec.networking.cilium.hubble.enabled=true --set=cluster.spec.certManager.enabled=true"
KUBETEST2_ARGS=()
KUBETEST2_ARGS+=("-v=2")

if [[ $1 == "kube-proxy" ]]; then
ARGS="${ARGS} --set=cluster.spec.networking.cilium.enableNodePort=false --set=cluster.spec.kubeProxy.enabled=true"
# This test requires private topology, which kubetest2 does not support.
#elif [[ $1 == "eni"]]
# ARGS="${ARGS} --set=cluster.spec.cilium.ipam=eni --set=cluster.spec.cilium.disable-masquerade"
# ARGS="${ARGS} --topology private"
elif [[ $1 == "node-local-dns" ]]; then
ARGS="${ARGS} --set=cluster.spec.kubeDNS.provider=CoreDNS --set=cluster.spec.kubeDNS.nodeLocalDNS.enabled=true"
if [[ "${JOB_TYPE}" == "presubmit" && "${REPO_OWNER}/${REPO_NAME}" == "kubernetes/kops" ]]; then
KUBETEST2_ARGS+=("--build")
KUBETEST2_ARGS+=("--kops-binary-path=${GOPATH}/src/k8s.io/kops/.build/dist/linux/$(go env GOARCH)/kops")
else
KUBETEST2_ARGS+=("--kops-version-marker=${KOPS_VERSION_MARKER:-https://storage.googleapis.com/k8s-staging-kops/kops/releases/markers/master/latest-ci.txt}")
fi

${KUBETEST2} \
--up \
--kubernetes-version="1.27.0" \
--kops-binary-path="${KOPS}" \
--create-args="--networking cilium $ARGS"

kubectl port-forward -n kube-system deployment/hubble-relay 4245:4245 &
CREATE_ARGS="--networking cilium --set=cluster.spec.networking.cilium.hubble.enabled=true --set=cluster.spec.certManager.enabled=true"

wget -qO- https://github.com/cilium/cilium-cli/releases/download/v0.14.8/cilium-linux-amd64.tar.gz | tar xz -C "${WORKSPACE}"
if [[ "${1:-}" == "kube-proxy" ]]; then
CREATE_ARGS="${CREATE_ARGS} --set=cluster.spec.networking.cilium.enableNodePort=false --set=cluster.spec.kubeProxy.enabled=true"
# This test requires private topology, which kubetest2 does not support.
#elif [[ "${1:-}" == "eni"]]
# CREATE_ARGS="${CREATE_ARGS} --set=cluster.spec.cilium.ipam=eni --set=cluster.spec.cilium.disable-masquerade"
# CREATE_ARGS="${CREATE_ARGS} --topology private"
elif [[ "${1:-}" == "node-local-dns" ]]; then
CREATE_ARGS="${CREATE_ARGS} --set=cluster.spec.kubeDNS.provider=CoreDNS --set=cluster.spec.kubeDNS.nodeLocalDNS.enabled=true"
fi

cilium connectivity test --all-flows
kubetest2 kops \
--up --down \
"${KUBETEST2_ARGS[@]}" \
--cloud-provider=aws \
--create-args="${CREATE_ARGS}" \
--kubernetes-version="https://dl.k8s.io/release/stable.txt" \
--test=exec -- "${TEST_ROOT}/test.sh"
26 changes: 26 additions & 0 deletions tests/e2e/scenarios/cilium-connectivity-test/test.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
#!/usr/bin/env bash

# Copyright 2026 The Kubernetes Authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

# Start hubble-relay port-forward in background
kubectl port-forward -n kube-system deployment/hubble-relay 4245:4245 &

# Download cilium-cli
CILIUM_CLI_VERSION="v0.14.8"
WORKSPACE="${WORKSPACE:-$(mktemp -d)}"
wget -qO- "https://github.com/cilium/cilium-cli/releases/download/${CILIUM_CLI_VERSION}/cilium-linux-amd64.tar.gz" | tar xz -C "${WORKSPACE}"

# Run connectivity test
"${WORKSPACE}/cilium" connectivity test --all-flows
Loading
Loading