mirror of
https://github.com/go-gost/gost.git
synced 2026-10-08 03:55:45 +00:00
test(e2e): add admission module e2e test suite
Verify service-level admission control gating by client source IP, in both whitelist and blacklist modes. Contrasts a loopback client (curl inside the gost container) against an external client (curl inside the echo container) to exercise both admit and deny paths.
This commit is contained in:
+17
@@ -0,0 +1,17 @@
|
||||
# HTTP proxy gated by a blacklist admission rule: clients whose source address
|
||||
# is 127.0.0.1 are denied; everything else is admitted. A loopback client (curl
|
||||
# inside the gost container) is denied; an external client (a different
|
||||
# container) is admitted and reaches the echo server.
|
||||
services:
|
||||
- name: proxy
|
||||
addr: ":8080"
|
||||
admission: admission-0
|
||||
handler:
|
||||
type: http
|
||||
listener:
|
||||
type: tcp
|
||||
|
||||
admissions:
|
||||
- name: admission-0
|
||||
matchers:
|
||||
- 127.0.0.1
|
||||
+18
@@ -0,0 +1,18 @@
|
||||
# HTTP proxy gated by a whitelist admission rule: only clients whose source
|
||||
# address is 127.0.0.1 are admitted. A loopback client (curl inside the gost
|
||||
# container) is admitted and reaches the echo server; an external client (a
|
||||
# different container) is denied at accept time.
|
||||
services:
|
||||
- name: proxy
|
||||
addr: ":8080"
|
||||
admission: admission-0
|
||||
handler:
|
||||
type: http
|
||||
listener:
|
||||
type: tcp
|
||||
|
||||
admissions:
|
||||
- name: admission-0
|
||||
whitelist: true
|
||||
matchers:
|
||||
- 127.0.0.1
|
||||
Reference in New Issue
Block a user