Skip to content

test: fix mismatched tls.key in tlsroute dynamic resolver testdata - #9582

Merged
arkodg merged 1 commit into
envoyproxy:mainfrom
zhaohuabing:fix/tlsroute-dynamic-resolver-testdata-key
Jul 26, 2026
Merged

test: fix mismatched tls.key in tlsroute dynamic resolver testdata#9582
arkodg merged 1 commit into
envoyproxy:mainfrom
zhaohuabing:fix/tlsroute-dynamic-resolver-testdata-key

Conversation

@zhaohuabing

@zhaohuabing zhaohuabing commented Jul 25, 2026

Copy link
Copy Markdown
Member

gen-check is currently failing on main. The tls-secret-1 added in #9184 for tlsroute-dynamic-resolver-with-tls-terminate.in.yaml has a outdated tls.key that doesn't match its tls.crt:

cert public key: 9ed3249631a87c80263964e9605eefbf
key  public key: 0e758100f16e94776901f5497cfddc2f

The tls-secret-1 added in envoyproxy#9184 for
tlsroute-dynamic-resolver-with-tls-terminate.in.yaml carries a tls.key
that does not match its tls.crt, so the secret fails validation:

  No valid secrets exist: envoy-gateway/tls-secret-1 must contain a
  matching tls.crt and tls.key: tls: private key does not match public key.

As a result the listener is never programmed, it is dropped from both
infraIR and xdsIR, and the TLSRoute reports ResolvedRefs=True instead of
the intended "Dynamic resolver backend is only supported with TLS
passthrough listeners" error. The test therefore no longer exercises the
dynamic resolver + TLS terminate path it was written for, and gen-check
fails on main because the committed .out.yaml does not match what the
translator now produces.

Replace tls.key with the key that actually matches tls.crt, the same one
used by the other 24 testdata files sharing this certificate. The
committed .out.yaml is correct as-is and is left unchanged.

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
@zhaohuabing
zhaohuabing requested a review from a team as a code owner July 25, 2026 23:49
@netlify

netlify Bot commented Jul 25, 2026

Copy link
Copy Markdown

Deploy Preview for cerulean-figolla-1f9435 ready!

Name Link
🔨 Latest commit 508bddc
🔍 Latest deploy log https://app.netlify.com/projects/cerulean-figolla-1f9435/deploys/6a654ba7935a640009f1aeb5
😎 Deploy Preview https://deploy-preview-9582--cerulean-figolla-1f9435.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@codecov

codecov Bot commented Jul 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 75.64%. Comparing base (8782e63) to head (508bddc).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #9582      +/-   ##
==========================================
- Coverage   75.64%   75.64%   -0.01%     
==========================================
  Files         252      253       +1     
  Lines       41758    41836      +78     
==========================================
+ Hits        31589    31645      +56     
- Misses       8046     8061      +15     
- Partials     2123     2130       +7     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@arkodg
arkodg merged commit 5c03eb7 into envoyproxy:main Jul 26, 2026
109 of 121 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants