Skip to content

agentgateway e2e lane fails on main since #1809: ateom-for-actor certificates carry no ActorIdentity extension #1922

Description

What happens

Since 8d6be5fb (#1809 by Taahir Ahmed (@ahmedtd), merged by Haven Xia (@HavenXia) 2026-09-25 21:34 UTC) the E2E (agentgateway) lane fails on every run of main and on every PR. The last green run on main was a0b680d7, three minutes earlier. The workflow conclusion stays success because the lane is continue-on-error, so nothing turned red on the branch page.

Failing tests, all in internal/e2e/suites/networking: TestActorEgress, TestActorEgressHTTPS, TestActorEgressGRPC, TestActorEgressNonStandardPort, TestActorEgressHTTPSByAddress, TestActorEgressPolicyAllowsByAddress, TestActorEgressPolicyDeniesUnlistedHost, TestActorEgressRequiresPolicy.

Signature: the actor's fetch through the egress gateway returns HTTP 502 with body read tcp 169.254.17.2:... -> <egress service>:80: read: connection reset by peer, repeated until the test's retry budget runs out.

The PR content does not matter. #1921 changes one comment line in a Go test on main 1d7ca8ce and fails the lane the same way (job, same eight tests, 216 connection-reset lines). So do #1904, #1905, #1906, #1910, #1917 and #1918.

Cause

#1809 switched atunnel from MintActorCertificate to MintAteomActorCertificate (internal/atunnel/credential.go). The new certificate carries the spiffe://.../ateom-for-actor/<atespace>/<name> URI SAN and no ActorIdentity x509 extension. The envoy dataplane reads the URI. The pinned agentgateway image, ghcr.io/agentgateway/agentgateway:v0.0.0-alpha.9f9744cf, resolves the actor in crates/agentgateway/src/http/substrate/egress_actor_resolution.rs from the extension, requires Purpose: atunnel, and denies the connection without it. That denial is the connection reset the tests see.

Fixes

Until one of them lands, every PR shows the lane red and reviewers cannot use it as a signal.

Activity

  1. dims commented on Sep 26, 2026

    @dims
    CollaboratorAuthor

    Looks like the fix is here:
    agentgateway/agentgateway#3677

    thanks Eitan Yarmush (@EItanya)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions