Skip to content

Instantly share code, notes, and snippets.

@rikatz
Last active June 19, 2026 13:45
Show Gist options
  • Select an option

  • Save rikatz/a56512ad5bf4a4fe67bba024dbc1d279 to your computer and use it in GitHub Desktop.

Select an option

Save rikatz/a56512ad5bf4a4fe67bba024dbc1d279 to your computer and use it in GitHub Desktop.
Creating a cluster for GW API Conformance

Simple script to create a KinD cluster ready for Gateway API conformance test

Remember to:

  • Change the address on metallb IPAddressPool to the right range
  • Bump versions as required

Call it with: ./gwapi.sh BACKEND

being backend:

  • istio
  • envoygw
  • kgateway
  • cilium
#!/usr/bin/env bash
#
set -x
BACKEND="${1:-envoygw}"
EXTRA_CONFIG="${EXTRA_CONFIG:-}"
CLUSTER_NAME="${CLUSTER_NAME:-kind}"
INSTALL_KUADRANT="${INSTALL_KUADRANT:-false}"
EXPERIMENTAL="${EXPERIMENTAL:-true}"
INSTALL_SAIL="${INSTALL_SAIL:-false}"
GATEWAYAPI_VERSION="${GATEWAYAPI_VERSION:-v1.5.1}"
create_kind() {
kind create cluster --name=${CLUSTER_NAME} ${EXTRA_CONFIG}
}
deploy_crds() {
CHANNEL=experimental
if [ "$EXPERIMENTAL" != "true" ]; then
CHANNEL="standard"
fi
kubectl apply --server-side -f https://github.com/kubernetes-sigs/gateway-api/releases/download/${GATEWAYAPI_VERSION}/${CHANNEL}-install.yaml
}
deploy_metallb() {
# kubectl apply -f https://raw.githubusercontent.com/metallb/metallb/v0.15.2/config/manifests/metallb-native.yaml
kubectl apply -f ./metallb-native.yaml
kubectl wait --timeout=5m deploy -n metallb-system controller --for=condition=Available
kubectl apply -f - <<EOF
apiVersion: metallb.io/v1beta1
kind: IPAddressPool
metadata:
namespace: metallb-system
name: kube-services
spec:
addresses:
- 172.18.200.100-172.18.200.150
---
apiVersion: metallb.io/v1beta1
kind: L2Advertisement
metadata:
name: kube-services
namespace: metallb-system
spec:
ipAddressPools:
- kube-services
EOF
}
case $BACKEND in
# NONE deploys no backend, just a bare cluster with metallb and CRDs
"none")
create_kind
deploy_crds
deploy_metallb
;;
"cilium")
EXTRA_CONFIG="--config=kind-cilium.yaml"
create_kind
deploy_crds
helm install cilium --namespace kube-system --version 1.19.1 \
--set image.pullPolicy=IfNotPresent --set ipam.mode=kubernetes \
--set gatewayAPI.enabled=true --set nodePort.enabled=true \
--set kubeProxyReplacement=true \
--set k8sServiceHost=kind-control-plane \
--set k8sServicePort=6443 \
--set operator.replicas=1 \
--set serviceAccounts.cilium.name=cilium \
--set serviceAccounts.operator.name=cilium-operator \
cilium --repo https://helm.cilium.io
kubectl wait --timeout=5m -n kube-system deployment/cilium-operator --for=condition=Available
kubectl wait --timeout=5m -n kube-system deployment/coredns --for=condition=Available
deploy_metallb
;;
"contour")
CONTOUR_VERSION=1.33
create_kind
deploy_crds
deploy_metallb
kubectl apply --server-side -f https://raw.githubusercontent.com/projectcontour/contour/refs/heads/release-${CONTOUR_VERSION}/examples/contour/01-crds.yaml
kubectl apply --server-side -f https://raw.githubusercontent.com/projectcontour/contour/refs/heads/release-${CONTOUR_VERSION}/examples/gateway-provisioner/00-common.yaml
kubectl apply --server-side -f https://raw.githubusercontent.com/projectcontour/contour/refs/heads/release-${CONTOUR_VERSION}/examples/gateway-provisioner/01-roles.yaml
kubectl apply --server-side -f https://raw.githubusercontent.com/projectcontour/contour/refs/heads/release-${CONTOUR_VERSION}/examples/gateway-provisioner/02-rolebindings.yaml
kubectl apply --server-side -f https://raw.githubusercontent.com/projectcontour/contour/refs/heads/release-${CONTOUR_VERSION}/examples/gateway-provisioner/03-gateway-provisioner.yaml
kubectl wait --timeout=5m -n projectcontour deployment/contour-gateway-provisioner --for=condition=Available
kubectl apply -f https://raw.githubusercontent.com/projectcontour/contour/refs/heads/release-${CONTOUR_VERSION}/examples/gateway/01-gatewayclass.yaml --dry-run=server -o yaml | sed 's/example/contour/' |kubectl apply -f -
;;
"envoygw")
create_kind
deploy_metallb
kubectl apply --server-side -f https://github.com/envoyproxy/gateway/releases/download/v1.8.0/install.yaml
kubectl wait --timeout=5m -n envoy-gateway-system deployment/envoy-gateway --for=condition=Available
kubectl apply -f https://github.com/envoyproxy/gateway/releases/download/v1.8.0/quickstart.yaml -n default
;;
"istio")
create_kind
deploy_crds
deploy_metallb
TAG=$(curl https://storage.googleapis.com/istio-build/dev/latest)
wget -c https://storage.googleapis.com/istio-build/dev/$TAG/istioctl-$TAG-linux-amd64.tar.gz
tar -xvf istioctl-$TAG-linux-amd64.tar.gz
./istioctl install --set values.pilot.env.PILOT_ENABLE_ALPHA_GATEWAY_API=${EXPERIMENTAL} --set values.pilot.env.ENABLE_GATEWAY_API_INFERENCE_EXTENSION=true --set values.pilot.env.PILOT_ENABLE_AGENTGATEWAY=true --set values.pilot.env.PILOT_ENABLE_GWXDS=true --set profile=minimal --skip-confirmation
;;
"kgateway")
create_kind
deploy_metallb
deploy_crds
helm upgrade -i --create-namespace --namespace kgateway-system --version v2.3.2 \
kgateway-crds oci://cr.kgateway.dev/kgateway-dev/charts/kgateway-crds \
--set controller.image.pullPolicy=Always
helm upgrade -i --namespace kgateway-system --version v2.3.2 \
kgateway oci://cr.kgateway.dev/kgateway-dev/charts/kgateway \
--set controller.image.pullPolicy=Always
;;
"agentgateway")
export AGENTGATEWAY_VERSION=v1.2.1
create_kind
deploy_metallb
deploy_crds
helm upgrade -i --create-namespace \
--namespace agentgateway-system \
--version "${AGENTGATEWAY_VERSION}" agentgateway-crds oci://cr.agentgateway.dev/charts/agentgateway-crds
helm upgrade -i agentgateway oci://cr.agentgateway.dev/charts/agentgateway \
--namespace agentgateway-system \
--version "${AGENTGATEWAY_VERSION}" \
--set controller.image.pullPolicy=Always \
--set controller.extraEnv.KGW_ENABLE_GATEWAY_API_EXPERIMENTAL_FEATURES=true
kubectl wait --timeout=5m deploy -n agentgateway-system agentgateway --for=condition=Available
;;
*)
echo "Invalid backend"
exit 1
;;
esac
if [ "${INSTALL_KUADRANT}" = "true" ]; then
helm install kuadrant-operator kuadrant-operator --create-namespace --namespace kuadrant-system --repo https://kuadrant.io/helm-charts/
fi
if [ "${INSTALL_SAIL}" = "true" ]; then
helm install sail-operator sail-operator --create-namespace --version 1.29.2 --namespace sail-operator --repo https://istio-ecosystem.github.io/sail-operator
fi
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment