What happens
Since 8d6be5fb (#1809 by Taahir Ahmed (@ahmedtd), merged by Haven Xia (@HavenXia) 2026-09-25 21:34 UTC) the E2E (agentgateway) lane fails on every run of main and on every PR. The last green run on main was a0b680d7, three minutes earlier. The workflow conclusion stays success because the lane is continue-on-error, so nothing turned red on the branch page.
Failing tests, all in internal/e2e/suites/networking: TestActorEgress, TestActorEgressHTTPS, TestActorEgressGRPC, TestActorEgressNonStandardPort, TestActorEgressHTTPSByAddress, TestActorEgressPolicyAllowsByAddress, TestActorEgressPolicyDeniesUnlistedHost, TestActorEgressRequiresPolicy.
Signature: the actor's fetch through the egress gateway returns HTTP 502 with body read tcp 169.254.17.2:... -> <egress service>:80: read: connection reset by peer, repeated until the test's retry budget runs out.
The PR content does not matter. #1921 changes one comment line in a Go test on main 1d7ca8ce and fails the lane the same way (job, same eight tests, 216 connection-reset lines). So do #1904, #1905, #1906, #1910, #1917 and #1918.
Cause
#1809 switched atunnel from MintActorCertificate to MintAteomActorCertificate (internal/atunnel/credential.go). The new certificate carries the spiffe://.../ateom-for-actor/<atespace>/<name> URI SAN and no ActorIdentity x509 extension. The envoy dataplane reads the URI. The pinned agentgateway image, ghcr.io/agentgateway/agentgateway:v0.0.0-alpha.9f9744cf, resolves the actor in crates/agentgateway/src/http/substrate/egress_actor_resolution.rs from the extension, requires Purpose: atunnel, and denies the connection without it. That denial is the connection reset the tests see.
Fixes
Until one of them lands, every PR shows the lane red and reviewers cannot use it as a signal.
What happens
Since
8d6be5fb(#1809 by Taahir Ahmed (@ahmedtd), merged by Haven Xia (@HavenXia) 2026-09-25 21:34 UTC) theE2E (agentgateway)lane fails on every run of main and on every PR. The last green run on main wasa0b680d7, three minutes earlier. The workflow conclusion stayssuccessbecause the lane iscontinue-on-error, so nothing turned red on the branch page.Failing tests, all in
internal/e2e/suites/networking:TestActorEgress,TestActorEgressHTTPS,TestActorEgressGRPC,TestActorEgressNonStandardPort,TestActorEgressHTTPSByAddress,TestActorEgressPolicyAllowsByAddress,TestActorEgressPolicyDeniesUnlistedHost,TestActorEgressRequiresPolicy.Signature: the actor's fetch through the egress gateway returns
HTTP 502with bodyread tcp 169.254.17.2:... -> <egress service>:80: read: connection reset by peer, repeated until the test's retry budget runs out.The PR content does not matter. #1921 changes one comment line in a Go test on main
1d7ca8ceand fails the lane the same way (job, same eight tests, 216 connection-reset lines). So do #1904, #1905, #1906, #1910, #1917 and #1918.Cause
#1809 switched atunnel from
MintActorCertificatetoMintAteomActorCertificate(internal/atunnel/credential.go). The new certificate carries thespiffe://.../ateom-for-actor/<atespace>/<name>URI SAN and noActorIdentityx509 extension. The envoy dataplane reads the URI. The pinned agentgateway image,ghcr.io/agentgateway/agentgateway:v0.0.0-alpha.9f9744cf, resolves the actor incrates/agentgateway/src/http/substrate/egress_actor_resolution.rsfrom the extension, requiresPurpose: atunnel, and denies the connection without it. That denial is the connection reset the tests see.Fixes
ActorIdentityextension back to the ateom-for-actor certificate, 27 lines. Its own agentgateway lane passes.manifests/ate-install/components/agentgateway/kustomization.yaml. After that ateapi: keep the ActorIdentity extension on ateom-for-actor certificates #1912's shim can go.Until one of them lands, every PR shows the lane red and reviewers cannot use it as a signal.