exec: [go test -json -tags=integ -timeout 180m ./tests/integration/security/policy_attachment_only -args -istio.test.skipWorkloads=tproxy,vm -istio.test.openshift -istio.test.kube.helm.values=global.platform=openshift -istio.test.istio.enableCNI=true -istio.test.ci=true -istio.test.env=kube -istio.test.kube.deploy=false -istio.test.stableNamespaces=true -istio.test.kube.deployGatewayAPI=false -istio.test.work_dir=/home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts] go test pid: 3520680 2025-06-24T14:41:20.737254Z warn unable to resolve TARGET_OUT. Dir /root/anurag/ossm3/istio/out/linux_ppc64le does not exist 2025-06-24T14:41:20.737320Z warn unable to resolve LOCAL_OUT. Dir /root/anurag/ossm3/istio/out/linux_ppc64le does not exist 2025-06-24T14:41:20.772575Z info tf === Test Framework Settings === 2025-06-24T14:41:20.772713Z info tf TestID: security_policy_attachment_only RunID: 6f13ffee-e099-48f0-8adf-02b1b40d54df NoCleanup: false BaseDir: /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts Selector: FailOnDeprecation: false CIMode: true Retries: 0 StableNamespaces: true Revision: SkipWorkloads [tproxy vm] Compatibility: false Revisions: Hub: quay.io/maistra Tag: ibm-p Variant: PullPolicy: Always PullSecret: MaxDumps: 10 HelmRepo: https://istio-release.storage.googleapis.com/charts GatewayConformanceStandardOnly: false 2025-06-24T14:41:20.772721Z info tf =============================== 2025-06-24T14:41:20.773899Z info tf Test run dir: /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts/security-policy-attachment-only- 2025-06-24T14:41:20.774000Z info tf Test Framework Kubernetes environment Settings: Kubeconfigs: [] LoadBalancerSupported: true MCSControllerEnabled: false ControlPlaneTopology: map[] NetworkTopology: map[] ConfigTopology: map[] 2025-06-24T14:41:20.774025Z info tf Flags istio.test.kube.config and istio.test.kube.topology not specified. 2025-06-24T14:41:20.774052Z info tf Using KubeConfigs: [/root/upi/cB/auth/kubeconfig]. 2025-06-24T14:41:20.774067Z info tf === BEGIN: Building clusters === 2025-06-24T14:41:20.777330Z info tf Built Cluster: Name: cluster-0 StableName: primary-0 PrimaryCluster: cluster-0 ConfigCluster: cluster-0 Network: HTTPProxy: ProxyKubectlOnly: false Filename: /root/upi/cB/auth/kubeconfig 2025-06-24T14:41:20.777339Z info tf === DONE: Building clusters === 2025-06-24T14:41:20.777360Z info tf === BEGIN: Setup: 'security_policy_attachment_only' === 2025-06-24T14:41:20.777382Z info tf === BEGIN: Deploy Istio [Suite=security_policy_attachment_only] === 2025-06-24T14:41:20.777388Z info tf === Istio Component Config === 2025-06-24T14:41:20.777429Z info tf SystemNamespace: istio-system TelemetryNamespace: istio-system DeployIstio: false DeployEastWestGW: true Values: map[global.hub:quay.io/maistra global.imagePullPolicy:Always global.platform:openshift global.tag:ibm-p global.variant:] PrimaryClusterIOPFile: tests/integration/iop-integration-test-defaults.yaml ConfigClusterIOPFile: tests/integration/iop-integration-test-defaults.yaml RemoteClusterIOPFile: tests/integration/iop-remote-integration-test-defaults.yaml BaseIOPFile: tests/integration/base.yaml SkipWaitForValidationWebhook: false DumpKubernetesManifests: false IstiodlessRemotes: true OperatorOptions: map[] EnableCNI: true IngressGatewayServiceName: IngressGatewayServiceNamespace: IngressGatewayIstioLabel: EgressGatewayServiceName: istio-egressgateway EgressGatewayServiceNamespace: istio-system EgressGatewayIstioLabel: egressgateway SharedMeshConfigName: 2025-06-24T14:41:20.777434Z info tf ================================ 2025-06-24T14:41:20.783351Z info tf skipping deployment as specified in the config 2025-06-24T14:41:20.783420Z info tf === SUCCEEDED: Deploy Istio in 6.03242ms [Suite=security_policy_attachment_only]=== 2025-06-24T14:41:20.783461Z info tf === BEGIN: Create namespace servers === 2025-06-24T14:41:20.783478Z info tf === BEGIN: Create namespace echo1 === 2025-06-24T14:41:20.848601Z info tf === SUCCEEDED: Create namespace echo1 in 65.134552ms === 2025-06-24T14:41:20.848764Z info tf === SUCCEEDED: Create namespace servers in 65.318984ms === 2025-06-24T14:41:20.848863Z info tf === BEGIN: Deploy JWT server === 2025-06-24T14:41:20.848919Z info tf === BEGIN: Create namespace external === 2025-06-24T14:41:20.848865Z info tf === BEGIN: Deploy authz server === 2025-06-24T14:41:20.848880Z info tf === BEGIN: Deploy local authz server (ns=echo1) === 2025-06-24T14:41:20.882556Z info tf patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true extensionProviders: - envoyExtAuthzHttp: headersToDownstreamOnDeny: - x-ext-authz-* headersToUpstreamOnAllow: - x-ext-authz-* includeAdditionalHeadersInCheck: x-ext-authz-additional-header-new: additional-header-new-value x-ext-authz-additional-header-override: additional-header-override-value includeRequestHeadersInCheck: - x-ext-authz port: 8000 service: ext-authz-http.echo1.local name: ext-authz-http-echo1-local - envoyExtAuthzGrpc: port: 9000 service: ext-authz-grpc.echo1.local name: ext-authz-grpc-echo1-local rootNamespace: istio-system trustDomain: cluster.local 2025-06-24T14:41:20.896656Z info tf === SUCCEEDED: Create namespace external in 47.736933ms === 2025-06-24T14:41:20.957441Z info tf === SUCCEEDED: Deploy local authz server (ns=echo1) in 108.56595ms === 2025-06-24T14:41:21.067776Z info tf Checking pods ready... 2025-06-24T14:41:21.067865Z info tf Checking pods ready... 2025-06-24T14:41:21.137407Z info tf No pods found... 2025-06-24T14:41:21.231004Z info tf === BEGIN: Deploy echo instances === 2025-06-24T14:41:21.337800Z info tf Checking pods ready... 2025-06-24T14:41:21.337849Z info tf Checking pods ready... 2025-06-24T14:41:21.378988Z info tf [ 0] jwt-server-7f5899d649-cvqsf Pending (Pending) 2025-06-24T14:41:21.779730Z info tf Checking pods ready... 2025-06-24T14:41:21.779770Z info tf Checking pods ready... 2025-06-24T14:41:22.030457Z info tf [ 0] jwt-server-7f5899d649-cvqsf Pending (Pending) 2025-06-24T14:41:22.377263Z info klog Waiting for caches to sync for echo 2025-06-24T14:41:22.413769Z info klog Waiting for caches to sync for echo 2025-06-24T14:41:22.477731Z info klog Caches are synced for echo 2025-06-24T14:41:22.485282Z info klog Waiting for caches to sync for echo 2025-06-24T14:41:22.489402Z info klog Waiting for caches to sync for echo 2025-06-24T14:41:22.495421Z info klog Waiting for caches to sync for echo 2025-06-24T14:41:22.496421Z info klog Waiting for caches to sync for echo 2025-06-24T14:41:22.498084Z info klog Waiting for caches to sync for echo 2025-06-24T14:41:22.503473Z info klog Waiting for caches to sync for echo 2025-06-24T14:41:22.513938Z info klog Caches are synced for echo 2025-06-24T14:41:22.527333Z info klog Waiting for caches to sync for echo 2025-06-24T14:41:22.586522Z info klog Caches are synced for echo 2025-06-24T14:41:22.590263Z info klog Caches are synced for echo 2025-06-24T14:41:22.595929Z info klog Caches are synced for echo 2025-06-24T14:41:22.597330Z info klog Caches are synced for echo 2025-06-24T14:41:22.598650Z info klog Caches are synced for echo 2025-06-24T14:41:22.604074Z info klog Caches are synced for echo 2025-06-24T14:41:22.627969Z info klog Caches are synced for echo 2025-06-24T14:41:22.830999Z info tf Checking pods ready... 2025-06-24T14:41:22.831105Z info tf Checking pods ready... 2025-06-24T14:41:22.848724Z info tf [ 0] jwt-server-7f5899d649-cvqsf Pending (Pending) 2025-06-24T14:41:24.449605Z info tf Checking pods ready... 2025-06-24T14:41:24.449702Z info tf Checking pods ready... 2025-06-24T14:41:24.455086Z info tf [ 0] jwt-server-7f5899d649-cvqsf Pending (Pending) 2025-06-24T14:41:27.655935Z info tf Checking pods ready... 2025-06-24T14:41:27.656050Z info tf Checking pods ready... 2025-06-24T14:41:27.662025Z info tf [ 0] jwt-server-7f5899d649-cvqsf Running (container not ready: 'istio-proxy') 2025-06-24T14:41:30.863683Z info tf Checking pods ready... 2025-06-24T14:41:30.863837Z info tf Checking pods ready... 2025-06-24T14:41:30.871454Z info tf [ 0] jwt-server-7f5899d649-cvqsf Running (container not ready: 'istio-proxy') 2025-06-24T14:41:34.044413Z info tf patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true extensionProviders: - envoyExtAuthzHttp: headersToDownstreamOnDeny: - x-ext-authz-* headersToUpstreamOnAllow: - x-ext-authz-* includeAdditionalHeadersInCheck: x-ext-authz-additional-header-new: additional-header-new-value x-ext-authz-additional-header-override: additional-header-override-value includeRequestHeadersInCheck: - x-ext-authz port: 8000 service: ext-authz.servers.svc.cluster.local name: ext-authz-http - envoyExtAuthzGrpc: port: 9000 service: ext-authz.servers.svc.cluster.local name: ext-authz-grpc rootNamespace: istio-system trustDomain: cluster.local 2025-06-24T14:41:34.044466Z info tf === SUCCEEDED: Deploy authz server in 13.195628785s === 2025-06-24T14:41:34.072287Z info tf Checking pods ready... 2025-06-24T14:41:34.072335Z info tf Checking pods ready... 2025-06-24T14:41:34.076788Z info tf [ 0] jwt-server-7f5899d649-cvqsf Running (Ready) 2025-06-24T14:41:34.081892Z info tf === SUCCEEDED: Deploy JWT server in 13.233048212s === 2025-06-24T14:42:33.563699Z error port forward failed: lost connection to pod 2025-06-24T14:42:33.990601Z warn pod: echo1/naked-v1-757556fc5c-q4t68 port forward terminated 2025-06-24T14:42:34.029252Z warn pod: echo1/naked-v1-757556fc5c-q4t68 port forward reconnect success 2025-06-24T14:42:34.112020Z error port forward failed: lost connection to pod 2025-06-24T14:42:34.486202Z warn pod: external/external-v1-f9d74566f-vzcxh port forward terminated 2025-06-24T14:42:34.518887Z warn pod: external/external-v1-f9d74566f-vzcxh port forward reconnect success 2025-06-24T14:42:37.550572Z error port forward failed: lost connection to pod 2025-06-24T14:42:37.777432Z warn pod: echo1/proxyless-grpc-v1-8996df688-jd9s6 port forward terminated 2025-06-24T14:42:37.827090Z warn pod: echo1/proxyless-grpc-v1-8996df688-jd9s6 port forward reconnect success 2025-06-24T14:43:36.962377Z info tf === SUCCEEDED: Deploy echo instances in 2m15.731370522s === 2025-06-24T14:43:36.998523Z info tf === DONE: Setup: 'security_policy_attachment_only' (2m16.221146846s) === 2025-06-24T14:43:36.998579Z info tf === BEGIN: Test Run: 'security_policy_attachment_only' === PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_without_token (5.73s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-1_token (0.05s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_sub-1_token_due_to_ignored_RequestAuthentication (0.02s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_sub-2_token (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_expired_token (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-1_token_on_any.com (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-2_token_on_any.com (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_without_token_on_any.com (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_token_on_other_host (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_healthz (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b (5.99s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only (6.16s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication (7.81s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/allow_with_sub-1_token (0.54s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_without_token (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_based_on_unacceptable_HTTP_method (0.02s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_based_on_unacceptable_HTTP_path (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b (0.68s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only (1.44s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy (2.51s) 2025-06-24T14:43:47.311559Z info tf === DONE: Test Run: 'security_policy_attachment_only' === 2025-06-24T14:43:47.311609Z info tf === Suite "security_policy_attachment_only" run time: 2m26.534251465s === 2025-06-24T14:43:47.311632Z info tf Wrote trace to /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts/trace.yaml 2025-06-24T14:43:47.345446Z info tf cleanup patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true rootNamespace: istio-system trustDomain: cluster.local 2025-06-24T14:43:47.621642Z info tf cleanup patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true rootNamespace: istio-system trustDomain: cluster.local 2025-06-24T14:43:47.682542Z info tf === BEGIN: Cleanup Istio [Suite=security_policy_attachment_only] === 2025-06-24T14:43:47.682618Z info tf === SUCCEEDED: Cleanup Istio in 58.439µs [Suite=security_policy_attachment_only] === PASS tests/integration/security/policy_attachment_only DONE 20 tests in 158.452s exec: go version