exec: [go test -json -tags=integ -timeout 180m ./tests/integration/security/policy_attachment_only -args -istio.test.skipWorkloads=tproxy,vm -istio.test.openshift -istio.test.kube.helm.values=global.platform=openshift -istio.test.istio.enableCNI=true -istio.test.ci=true -istio.test.env=kube -istio.test.kube.deploy=false -istio.test.stableNamespaces=true -istio.test.kube.deployGatewayAPI=false -istio.test.gatewayConformance.maxTimeToConsistency=180s -istio.test.work_dir=/home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts] go test pid: 2671910 go: downloading istio.io/api v1.26.3-0.20250708203130-20827773ee1b go: downloading sigs.k8s.io/gateway-api v1.3.0 go: downloading istio.io/client-go v1.26.3-0.20250708203830-38d6e685077d go: downloading k8s.io/apiserver v0.33.2 go: downloading k8s.io/kubectl v0.33.2 go: downloading k8s.io/cli-runtime v0.33.2 go: downloading github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 go: downloading golang.org/x/crypto v0.39.0 go: downloading golang.org/x/net v0.40.0 go: downloading helm.sh/helm/v3 v3.18.4 go: downloading github.com/google/cel-go v0.23.2 go: downloading github.com/miekg/dns v1.1.65 go: downloading sigs.k8s.io/kustomize/api v0.19.0 go: downloading sigs.k8s.io/kustomize/kyaml v0.19.0 go: downloading github.com/envoyproxy/go-control-plane v0.13.5-0.20250415164843-6e146b543742 go: downloading k8s.io/component-base v0.33.2 go: downloading github.com/BurntSushi/toml v1.5.0 go: downloading github.com/cyphar/filepath-securejoin v0.4.1 go: downloading k8s.io/component-helpers v0.33.2 go: downloading github.com/opencontainers/image-spec v1.1.1 2025-08-04T09:03:18.174062Z warn unable to resolve TARGET_OUT. Dir /root/mohit/istio/out/linux_ppc64le does not exist 2025-08-04T09:03:18.174108Z warn unable to resolve LOCAL_OUT. Dir /root/mohit/istio/out/linux_ppc64le does not exist 2025-08-04T09:03:18.201176Z info tf === Test Framework Settings === 2025-08-04T09:03:18.201237Z info tf TestID: security_policy_attachment_only RunID: c684bd11-839d-4e80-b2c4-3aed4599040a NoCleanup: false BaseDir: /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts Selector: FailOnDeprecation: false CIMode: true Retries: 0 StableNamespaces: true Revision: SkipWorkloads [tproxy vm] Compatibility: false Revisions: Hub: quay.io/maistra Tag: ibm-p Variant: PullPolicy: Always PullSecret: MaxDumps: 10 HelmRepo: https://istio-release.storage.googleapis.com/charts IPFamilies: [] GatewayConformanceStandardOnly: false GatewayConformanceAllowCRDsMismatch: false 2025-08-04T09:03:18.201242Z info tf =============================== 2025-08-04T09:03:18.201619Z info tf Test run dir: /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts/security-policy-attachment-only- 2025-08-04T09:03:18.201650Z info tf Test Framework Kubernetes environment Settings: Kubeconfigs: [] LoadBalancerSupported: true MCSControllerEnabled: false ControlPlaneTopology: map[] NetworkTopology: map[] ConfigTopology: map[] 2025-08-04T09:03:18.201657Z info tf Flags istio.test.kube.config and istio.test.kube.topology not specified. 2025-08-04T09:03:18.201672Z info tf Using KubeConfigs: [/root/upi/cA/auth/kubeconfig]. 2025-08-04T09:03:18.201678Z info tf === BEGIN: Building clusters === 2025-08-04T09:03:18.205480Z info tf Built Cluster: Name: cluster-0 StableName: primary-0 PrimaryCluster: cluster-0 ConfigCluster: cluster-0 Network: HTTPProxy: ProxyKubectlOnly: false Filename: /root/upi/cA/auth/kubeconfig 2025-08-04T09:03:18.205488Z info tf === DONE: Building clusters === 2025-08-04T09:03:18.205506Z info tf === BEGIN: Setup: 'security_policy_attachment_only' === 2025-08-04T09:03:18.205536Z info tf === BEGIN: Deploy Istio [Suite=security_policy_attachment_only] === 2025-08-04T09:03:18.205544Z info tf === Istio Component Config === 2025-08-04T09:03:18.205580Z info tf SystemNamespace: istio-system TelemetryNamespace: istio-system DeployIstio: false DeployEastWestGW: true Values: map[global.hub:quay.io/maistra global.imagePullPolicy:Always global.platform:openshift global.tag:ibm-p global.variant:] PrimaryClusterIOPFile: tests/integration/iop-integration-test-defaults.yaml ConfigClusterIOPFile: tests/integration/iop-integration-test-defaults.yaml RemoteClusterIOPFile: tests/integration/iop-remote-integration-test-defaults.yaml BaseIOPFile: tests/integration/base.yaml SkipWaitForValidationWebhook: false DumpKubernetesManifests: false IstiodlessRemotes: true OperatorOptions: map[] EnableCNI: true IngressGatewayServiceName: IngressGatewayServiceNamespace: IngressGatewayIstioLabel: EgressGatewayServiceName: istio-egressgateway EgressGatewayServiceNamespace: istio-system EgressGatewayIstioLabel: egressgateway SharedMeshConfigName: ControlPlaneInstaller: 2025-08-04T09:03:18.205585Z info tf ================================ 2025-08-04T09:03:18.210627Z info tf skipping deployment as specified in the config 2025-08-04T09:03:18.210675Z info tf === SUCCEEDED: Deploy Istio in 5.133496ms [Suite=security_policy_attachment_only]=== 2025-08-04T09:03:18.210710Z info tf === BEGIN: Create namespace servers === 2025-08-04T09:03:18.210730Z info tf === BEGIN: Create namespace echo1 === 2025-08-04T09:03:18.289752Z info tf === SUCCEEDED: Create namespace echo1 in 79.017323ms === 2025-08-04T09:03:18.294328Z info tf === SUCCEEDED: Create namespace servers in 83.621204ms === 2025-08-04T09:03:18.294403Z info tf === BEGIN: Deploy authz server === 2025-08-04T09:03:18.294439Z info tf === BEGIN: Deploy JWT server === 2025-08-04T09:03:18.294477Z info tf === BEGIN: Create namespace external === 2025-08-04T09:03:18.294464Z info tf === BEGIN: Deploy local authz server (ns=echo1) === 2025-08-04T09:03:18.394750Z info tf patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true extensionProviders: - envoyExtAuthzHttp: headersToDownstreamOnDeny: - x-ext-authz-* headersToUpstreamOnAllow: - x-ext-authz-* includeAdditionalHeadersInCheck: x-ext-authz-additional-header-new: additional-header-new-value x-ext-authz-additional-header-override: additional-header-override-value includeRequestHeadersInCheck: - x-ext-authz port: 8000 service: ext-authz-http.echo1.local name: ext-authz-http-echo1-local - envoyExtAuthzGrpc: port: 9000 service: ext-authz-grpc.echo1.local name: ext-authz-grpc-echo1-local rootNamespace: istio-system trustDomain: cluster.local 2025-08-04T09:03:18.443449Z info tf === SUCCEEDED: Create namespace external in 148.972889ms === 2025-08-04T09:03:18.628259Z info tf === SUCCEEDED: Deploy local authz server (ns=echo1) in 333.81673ms === 2025-08-04T09:03:18.893764Z info tf === BEGIN: Deploy echo instances === 2025-08-04T09:03:20.290015Z info tf Checking pods ready... 2025-08-04T09:03:20.290119Z info tf Checking pods ready... 2025-08-04T09:03:21.095032Z info tf No pods found... 2025-08-04T09:03:21.295827Z info tf Checking pods ready... 2025-08-04T09:03:21.295959Z info tf Checking pods ready... 2025-08-04T09:03:22.747268Z info tf [ 0] jwt-server-789549f577-xddl7 Pending (Pending) 2025-08-04T09:03:23.147433Z info tf Checking pods ready... 2025-08-04T09:03:23.147462Z info tf Checking pods ready... 2025-08-04T09:03:23.238096Z info tf [ 0] jwt-server-789549f577-xddl7 Pending (Pending) 2025-08-04T09:03:24.039250Z info tf Checking pods ready... 2025-08-04T09:03:24.039304Z info tf Checking pods ready... 2025-08-04T09:03:24.432943Z info tf [ 0] jwt-server-789549f577-xddl7 Pending (Pending) 2025-08-04T09:03:26.033855Z info tf Checking pods ready... 2025-08-04T09:03:26.033934Z info tf Checking pods ready... 2025-08-04T09:03:27.027010Z info tf [ 0] jwt-server-789549f577-xddl7 Pending (Pending) 2025-08-04T09:03:29.453698Z info klog Waiting for caches to sync controller=echo 2025-08-04T09:03:29.554711Z info klog Caches are synced controller=echo 2025-08-04T09:03:29.559992Z info klog Waiting for caches to sync controller=echo 2025-08-04T09:03:29.590759Z info klog Waiting for caches to sync controller=echo 2025-08-04T09:03:29.592353Z info klog Waiting for caches to sync controller=echo 2025-08-04T09:03:29.651669Z info klog Waiting for caches to sync controller=echo 2025-08-04T09:03:29.660343Z info klog Caches are synced controller=echo 2025-08-04T09:03:29.676188Z info klog Waiting for caches to sync controller=echo 2025-08-04T09:03:29.691104Z info klog Caches are synced controller=echo 2025-08-04T09:03:29.692785Z info klog Caches are synced controller=echo 2025-08-04T09:03:29.701653Z info klog Waiting for caches to sync controller=echo 2025-08-04T09:03:29.712495Z info klog Waiting for caches to sync controller=echo 2025-08-04T09:03:29.752717Z info klog Caches are synced controller=echo 2025-08-04T09:03:29.777281Z info klog Caches are synced controller=echo 2025-08-04T09:03:29.802075Z info klog Caches are synced controller=echo 2025-08-04T09:03:29.813012Z info klog Caches are synced controller=echo 2025-08-04T09:03:29.821927Z info klog Waiting for caches to sync controller=echo 2025-08-04T09:03:29.922491Z info klog Caches are synced controller=echo 2025-08-04T09:03:30.227982Z info tf Checking pods ready... 2025-08-04T09:03:30.228014Z info tf Checking pods ready... 2025-08-04T09:03:30.475325Z info tf [ 0] jwt-server-789549f577-xddl7 Running (Ready) 2025-08-04T09:03:30.779771Z info tf === SUCCEEDED: Deploy JWT server in 12.485344763s === 2025-08-04T09:03:31.191045Z info tf patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true extensionProviders: - envoyExtAuthzHttp: headersToDownstreamOnDeny: - x-ext-authz-* headersToUpstreamOnAllow: - x-ext-authz-* includeAdditionalHeadersInCheck: x-ext-authz-additional-header-new: additional-header-new-value x-ext-authz-additional-header-override: additional-header-override-value includeRequestHeadersInCheck: - x-ext-authz port: 8000 service: ext-authz.servers.svc.cluster.local name: ext-authz-http - envoyExtAuthzGrpc: port: 9000 service: ext-authz.servers.svc.cluster.local name: ext-authz-grpc rootNamespace: istio-system trustDomain: cluster.local 2025-08-04T09:03:31.191137Z info tf === SUCCEEDED: Deploy authz server in 12.896740401s === 2025-08-04T09:03:40.911153Z info tf === SUCCEEDED: Deploy echo instances in 22.017382775s === 2025-08-04T09:03:40.993357Z info tf === DONE: Setup: 'security_policy_attachment_only' (22.787834245s) === 2025-08-04T09:03:40.993423Z info tf === BEGIN: Test Run: 'security_policy_attachment_only' === PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_without_token (4.22s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-1_token (0.05s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_sub-1_token_due_to_ignored_RequestAuthentication (0.02s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_sub-2_token (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_expired_token (0.02s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-1_token_on_any.com (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-2_token_on_any.com (0.02s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_without_token_on_any.com (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_token_on_other_host (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_healthz (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b (4.42s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only (4.92s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication (5.98s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/allow_with_sub-1_token (4.27s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_without_token (0.02s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_based_on_unacceptable_HTTP_method (0.03s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_based_on_unacceptable_HTTP_path (0.02s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b (4.60s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only (9.18s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy (12.53s) 2025-08-04T09:03:59.505480Z info tf === DONE: Test Run: 'security_policy_attachment_only' === 2025-08-04T09:03:59.505546Z info tf === Suite "security_policy_attachment_only" run time: 41.300043532s === 2025-08-04T09:03:59.505561Z info tf Wrote trace to /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts/trace.yaml 2025-08-04T09:03:59.534844Z info tf cleanup patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true rootNamespace: istio-system trustDomain: cluster.local 2025-08-04T09:03:59.918566Z info tf cleanup patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true rootNamespace: istio-system trustDomain: cluster.local 2025-08-04T09:04:00.078901Z info tf === BEGIN: Cleanup Istio [Suite=security_policy_attachment_only] === 2025-08-04T09:04:00.078933Z info tf === SUCCEEDED: Cleanup Istio in 26.571µs [Suite=security_policy_attachment_only] === PASS tests/integration/security/policy_attachment_only DONE 20 tests in 41.932s exec: go version