test(e2e): add admission module e2e test suite

Verify service-level admission control gating by client source IP, in
both whitelist and blacklist modes. Contrasts a loopback client (curl
inside the gost container) against an external client (curl inside the
echo container) to exercise both admit and deny paths.
This commit is contained in:
ginuerzh
2026-07-16 20:53:30 +08:00
parent c7ea19ec66
commit 3119cb43f2
3 changed files with 146 additions and 0 deletions
+18
View File
@@ -0,0 +1,18 @@
# HTTP proxy gated by a whitelist admission rule: only clients whose source
# address is 127.0.0.1 are admitted. A loopback client (curl inside the gost
# container) is admitted and reaches the echo server; an external client (a
# different container) is denied at accept time.
services:
- name: proxy
addr: ":8080"
admission: admission-0
handler:
type: http
listener:
type: tcp
admissions:
- name: admission-0
whitelist: true
matchers:
- 127.0.0.1