Sitelet https://github.com/kubernetes/kops/pull/18517
Skip to content

tests/e2e: also skip implement-NodePort ETP=Local test on calico+GCE - #18517

Merged
kubernetes-prow[bot] merged 1 commit into
kubernetes:masterfrom
rifelpet:skip-etp-local-gce-calico
Jun 28, 2026
Merged

kubernetes-prow[bot] merged 1 commit into
kubernetes:masterfrom
rifelpet:skip-etp-local-gce-calico

Conversation

@rifelpet

@rifelpet rifelpet commented Jun 27, 2026 •

Copy link
Copy Markdown
Member

What

Follow-up to the recent change that runs Services should implement NodePort and HealthCheckNodePort correctly when ExternalTrafficPolicy changes on non-Cilium CNIs (#18515). The test fails on calico on GCE but passes on calico on AWS:

Root cause

The test runs a hostNetwork pod on node A that curls node B's NodePort with the source bound to node A's IP; with externalTrafficPolicy=Local, node B must deliver to a local backend without SNAT so the client IP is preserved.

GCE calico AWS calico
Inter-node pod routes ... via <nodeIP> **dev tunl0** proto bird onlink ... via <nodeIP> **dev ens5** proto bird
Encapsulation IPIP (tunl0) none — native VPC
MTU 1440 (IPIP overhead) 8981

The bad source 100.117.161.64 is exactly node A's /26 IPIP block base (100.117.161.64/26 via 10.0.16.6 dev tunl0) — its tunl0 tunnel address. The IPIP/masquerade path rewrites the source, losing the client IP.

kops sets calico to IPIP CrossSubnet on both clouds. The difference:

  • AWS: kops disables the EC2 source/dest check, so the VPC forwards calico pod-CIDR packets → calico routes natively (no encap) → source IP preserved.
  • GCE: the VPC drops packets with arbitrary pod-CIDR source/dest (anti-spoofing), so calico must IPIP-encapsulate all inter-node pod traffic → source IP rewritten.

This is a fundamental calico-IPIP-overlay-on-GCE limitation (same SNAT class as Cilium's overlay), not a kops bug. Corroborated by the rest of the GCE matrix: ipalias (alias IPs), kindnet and kubenet (GCE routes) all route natively and pass; only the calico overlay fails.

Change

Extend the skip to calico when the cloud provider is GCE. amazon-vpc and kindnet keep running the test on both clouds, and calico keeps running it on AWS (where it passes).

The "Services should implement NodePort and HealthCheckNodePort correctly
when ExternalTrafficPolicy changes" test fails on calico on GCE but passes
on calico on AWS.

On GCE the VPC drops packets with arbitrary calico pod-CIDR source/dest
addresses, so calico must IPIP-encapsulate inter-node pod traffic (routes go
via tunl0). The IPIP/masquerade path rewrites the ETP=Local NodePort
traffic's source to the node's tunnel address (a pod-CIDR IP) instead of
preserving the client IP. On AWS kops disables the EC2 source/dest check, so
calico routes pod traffic natively over the VPC (dev ens5, no encapsulation)
and the source IP is preserved.

Extend the skip to calico when the cloud provider is GCE. amazon-vpc and
kindnet continue running the test on both clouds.
@kubernetes-prow kubernetes-prow Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jun 27, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@kubernetes-prow kubernetes-prow Bot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jun 27, 2026
@kubernetes-prow
kubernetes-prow Bot requested review from olemarkus and zetaab June 27, 2026 20:44
@kubernetes-prow kubernetes-prow Bot added the cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. label Jun 27, 2026
@rifelpet
rifelpet marked this pull request as ready for review June 27, 2026 20:45
@kubernetes-prow kubernetes-prow Bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jun 27, 2026
@kubernetes-prow
kubernetes-prow Bot requested a review from hakman June 27, 2026 20:47
@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jun 28, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: hakman

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jun 28, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit 07f4dd0 into kubernetes:master Jun 28, 2026
27 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants