chore: add test for EG cert rotation #4944
Draft
+227
−11
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What type of PR is this?
What this PR does / why we need it:
In #4481, TLS config loading was changed to load the latest certs when a new client connection is established:
gateway/internal/crypto/cert_load.go
Line 54 in 2385672
This effectively made it possible to rotate certificate without restarting the xds runner.
This PR adds an e2e test that rotates Envoy Gateway/Envoy certificates and verifies that clients using rotated certs are able to connect to EG (which picks up the new cert). EG XDS is exposed with LB SVC for convenience.
rotation can take several seconds:
Which issue(s) this PR fixes:
Relates to #4891
Release Notes: No