tests/e2e: skip implement-NodePort ETP=Local test on more CNIs - #18515
Merged
kubernetes-prow[bot] merged 1 commit intoJun 27, 2026
Merged
kubernetes-prow[bot] merged 1 commit into
kubernetes-prow[bot] merged 1 commit into
Conversation
The "Services should implement NodePort and HealthCheckNodePort correctly when ExternalTrafficPolicy changes" test was previously gated to Cilium only, but the e2e-kops-aws-cni-* periodic jobs show it also fails on flannel, kopeio and kube-router: the client source IP is SNATed to a pod IP instead of being preserved (kube-router instead times out reaching the local endpoint). It is the sole failure in those three jobs' latest runs. Move it out of the Cilium block into a condition covering cilium, flannel, kopeio and kube-router. amazon-vpc, calico and kindnet preserve the source IP and continue running the test. The sibling "externalTrafficPolicy=Local for type=NodePort" test passes on every non-Cilium CNI, so it stays gated to Cilium only.
Contributor
|
Skipping CI for Draft Pull Request. |
rifelpet
marked this pull request as ready for review
June 27, 2026 01:31
hakman
approved these changes
Jun 27, 2026
Contributor
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: hakman The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
followup to #18509
What
Follow-up to the recently merged change that moved the
Services should implement NodePort and HealthCheckNodePort correctly when ExternalTrafficPolicy changesskip into the Cilium block.Inspecting the latest
e2e-kops-aws-cni-*periodic runs shows that gating it to Cilium alone was too narrow — the test also fails on flannel, kopeio, and kube-router, and it is the sole failure in each of those three jobs' latest runs (i.e. it turned them red):100.96.3.0!= node172.20.200.197)100.96.2.0!= node172.20.113.68)context deadline exceeded)All three share the same root cause:
externalTrafficPolicy=Localsource-IP preservation is not implemented (kube-router fails one step earlier with a connectivity timeout).Change
Move the skip out of the Cilium-only block into a condition covering cilium, flannel, kopeio, and kube-router. amazon-vpc, calico, and kindnet preserve the source IP and keep running the test.
The sibling
externalTrafficPolicy=Local for type=NodePorttest passes on every non-Cilium CNI, so it stays gated to Cilium only.