From 98eaa85ee554c0b961b102527cc3fed92920856a Mon Sep 17 00:00:00 2001 From: Richard Wall Date: Tue, 6 Oct 2026 12:58:53 +0000 Subject: [PATCH] Create the e2e GKE cluster with private nodes and no public control-plane IP - The nightly e2e started failing on 2026-10-06 because a new org policy on the CI project rejects GKE clusters with public nodes or a public control-plane endpoint. - Create the cluster with private nodes and a private IP endpoint, and use the DNS-based endpoint so the GitHub runner can still reach the API server. - The private nodes depend on a Cloud NAT in the project's default network. The CI service account cannot create one, so it must be set up separately. Co-Authored-By: Claude Signed-off-by: Richard Wall --- hack/e2e/test.sh | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/hack/e2e/test.sh b/hack/e2e/test.sh index 83e75d16..946a2783 100755 --- a/hack/e2e/test.sh +++ b/hack/e2e/test.sh @@ -75,12 +75,23 @@ source release.env popd export USE_GKE_GCLOUD_AUTH_PLUGIN=True -if ! gcloud container clusters get-credentials "${CLUSTER_NAME}"; then + +# The project's org policy forbids GKE nodes with public IPs and a public +# control-plane IP. The nodes rely on a Cloud NAT in the default network to +# reach the Venafi API and the image registries. The DNS endpoint is reachable +# from the GitHub runner and is authorised with IAM. +# Why?: https://cloud.google.com/kubernetes-engine/docs/concepts/network-isolation#dns-based_endpoint +if ! gcloud container clusters describe "${CLUSTER_NAME}" &>/dev/null; then gcloud container clusters create "${CLUSTER_NAME}" \ --preemptible \ --machine-type e2-small \ - --num-nodes 3 + --num-nodes 3 \ + --enable-ip-alias \ + --enable-private-nodes \ + --enable-private-endpoint \ + --enable-dns-access fi +gcloud container clusters get-credentials "${CLUSTER_NAME}" --dns-endpoint kubectl create ns venafi || true # Pull secret for Venafi OCI registry