integration: remove exit node via grant tests
Remove TestGrantViaExitNodeSteering and TestGrantViaMixedSteering. Exit node traffic forwarding through via grants cannot be validated with curl/traceroute in Docker containers because Tailscale exit nodes strip locally-connected subnets from their forwarding filter. The correctness of via exit steering is validated by: - Golden MapResponse comparison (TestViaGrantMapCompat with GRANT-V31 and GRANT-V36) comparing full netmap output against Tailscale SaaS - Filter rule compatibility (TestGrantsCompat with GRANT-V14 through GRANT-V36) comparing per-node PacketFilter rules against Tailscale SaaS - TestGrantViaSubnetSteering (kept) validates via subnet steering with actual curl/traceroute through Docker, which works for subnet routes Updates #2180
This commit is contained in:
parent
c36cedc32f
commit
b762e4c350
5 changed files with 55 additions and 903 deletions
|
|
@ -1007,13 +1007,6 @@ func tagApprover(name string) policyv2.AutoApprover {
|
|||
return new(policyv2.Tag(name))
|
||||
}
|
||||
|
||||
// autogroupp returns a pointer to an AutoGroup as an Alias for policy v2 configurations.
|
||||
// Used in grant rules to reference autogroups like autogroup:self and autogroup:internet.
|
||||
func autogroupp(name string) policyv2.Alias {
|
||||
ag := policyv2.AutoGroup(name)
|
||||
return &ag
|
||||
}
|
||||
|
||||
// oidcMockUser creates a MockUser for OIDC authentication testing.
|
||||
// Generates consistent test user data with configurable email verification status
|
||||
// for validating OIDC integration flows in headscale authentication tests.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue