exec: [go test -json -tags=integ -timeout 180m ./tests/integration/security/policy_attachment_only -args -istio.test.skipWorkloads=tproxy,vm -istio.test.openshift -istio.test.kube.helm.values=global.platform=openshift -istio.test.istio.enableCNI=true -istio.test.ci=true -istio.test.env=kube -istio.test.kube.deploy=false -istio.test.stableNamespaces=true -istio.test.kube.deployGatewayAPI=false -istio.test.gatewayConformance.maxTimeToConsistency=180s -istio.test.work_dir=/home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts] go test pid: 267151 2025-08-04T08:37:34.385156Z warn unable to resolve TARGET_OUT. Dir /root/afsan/istio/out/linux_ppc64le does not exist 2025-08-04T08:37:34.385246Z warn unable to resolve LOCAL_OUT. Dir /root/afsan/istio/out/linux_ppc64le does not exist 2025-08-04T08:37:34.420697Z info tf === Test Framework Settings === 2025-08-04T08:37:34.420835Z info tf TestID: security_policy_attachment_only RunID: 6c6d711b-2ac0-4654-ba8b-8869db4cee5c NoCleanup: false BaseDir: /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts Selector: FailOnDeprecation: false CIMode: true Retries: 0 StableNamespaces: true Revision: SkipWorkloads [tproxy vm] Compatibility: false Revisions: Hub: quay.io/maistra Tag: ibm-p Variant: PullPolicy: Always PullSecret: MaxDumps: 10 HelmRepo: https://istio-release.storage.googleapis.com/charts IPFamilies: [] GatewayConformanceStandardOnly: false GatewayConformanceAllowCRDsMismatch: false 2025-08-04T08:37:34.420842Z info tf =============================== 2025-08-04T08:37:34.422019Z info tf Test run dir: /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts/security-policy-attachment-only- 2025-08-04T08:37:34.422457Z info tf Test Framework Kubernetes environment Settings: Kubeconfigs: [] LoadBalancerSupported: true MCSControllerEnabled: false ControlPlaneTopology: map[] NetworkTopology: map[] ConfigTopology: map[] 2025-08-04T08:37:34.422489Z info tf Flags istio.test.kube.config and istio.test.kube.topology not specified. 2025-08-04T08:37:34.422502Z info tf Environment variable KUBECONFIG unspecified, defaulting to ~/.kube/config. 2025-08-04T08:37:34.422760Z info tf Using KubeConfigs: [/root/.kube/config]. 2025-08-04T08:37:34.422778Z info tf === BEGIN: Building clusters === 2025-08-04T08:37:34.426803Z info tf Built Cluster: Name: cluster-0 StableName: primary-0 PrimaryCluster: cluster-0 ConfigCluster: cluster-0 Network: HTTPProxy: ProxyKubectlOnly: false Filename: /root/.kube/config 2025-08-04T08:37:34.426880Z info tf === DONE: Building clusters === 2025-08-04T08:37:34.426921Z info tf === BEGIN: Setup: 'security_policy_attachment_only' === 2025-08-04T08:37:34.426963Z info tf === BEGIN: Deploy Istio [Suite=security_policy_attachment_only] === 2025-08-04T08:37:34.426974Z info tf === Istio Component Config === 2025-08-04T08:37:34.427036Z info tf SystemNamespace: istio-system TelemetryNamespace: istio-system DeployIstio: false DeployEastWestGW: true Values: map[global.hub:quay.io/maistra global.imagePullPolicy:Always global.platform:openshift global.tag:ibm-p global.variant:] PrimaryClusterIOPFile: tests/integration/iop-integration-test-defaults.yaml ConfigClusterIOPFile: tests/integration/iop-integration-test-defaults.yaml RemoteClusterIOPFile: tests/integration/iop-remote-integration-test-defaults.yaml BaseIOPFile: tests/integration/base.yaml SkipWaitForValidationWebhook: false DumpKubernetesManifests: false IstiodlessRemotes: true OperatorOptions: map[] EnableCNI: true IngressGatewayServiceName: IngressGatewayServiceNamespace: IngressGatewayIstioLabel: EgressGatewayServiceName: istio-egressgateway EgressGatewayServiceNamespace: istio-system EgressGatewayIstioLabel: egressgateway SharedMeshConfigName: ControlPlaneInstaller: 2025-08-04T08:37:34.427046Z info tf ================================ 2025-08-04T08:37:34.429793Z info tf skipping deployment as specified in the config 2025-08-04T08:37:34.429808Z info tf === SUCCEEDED: Deploy Istio in 2.840398ms [Suite=security_policy_attachment_only]=== 2025-08-04T08:37:34.429846Z info tf === BEGIN: Create namespace servers === 2025-08-04T08:37:34.429880Z info tf === BEGIN: Create namespace echo1 === 2025-08-04T08:37:34.447952Z info tf === SUCCEEDED: Create namespace servers in 18.102748ms === 2025-08-04T08:37:34.454178Z info tf === SUCCEEDED: Create namespace echo1 in 24.312911ms === 2025-08-04T08:37:34.454302Z info tf === BEGIN: Create namespace external === 2025-08-04T08:37:34.454294Z info tf === BEGIN: Deploy authz server === 2025-08-04T08:37:34.454300Z info tf === BEGIN: Deploy JWT server === 2025-08-04T08:37:34.454338Z info tf === BEGIN: Deploy local authz server (ns=echo1) === 2025-08-04T08:37:34.467314Z info tf === SUCCEEDED: Create namespace external in 13.010538ms === 2025-08-04T08:37:34.475994Z info tf patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true extensionProviders: - envoyExtAuthzHttp: headersToDownstreamOnDeny: - x-ext-authz-* headersToUpstreamOnAllow: - x-ext-authz-* includeAdditionalHeadersInCheck: x-ext-authz-additional-header-new: additional-header-new-value x-ext-authz-additional-header-override: additional-header-override-value includeRequestHeadersInCheck: - x-ext-authz port: 8000 service: ext-authz-http.echo1.local name: ext-authz-http-echo1-local - envoyExtAuthzGrpc: port: 9000 service: ext-authz-grpc.echo1.local name: ext-authz-grpc-echo1-local rootNamespace: istio-system trustDomain: cluster.local 2025-08-04T08:37:34.522031Z info tf === SUCCEEDED: Deploy local authz server (ns=echo1) in 67.714082ms === 2025-08-04T08:37:34.523872Z info tf Checking pods ready... 2025-08-04T08:37:34.523920Z info tf Checking pods ready... 2025-08-04T08:37:34.541370Z info tf No pods found... 2025-08-04T08:37:34.594269Z info tf === BEGIN: Deploy echo instances === 2025-08-04T08:37:34.742043Z info tf Checking pods ready... 2025-08-04T08:37:34.742098Z info tf Checking pods ready... 2025-08-04T08:37:34.749900Z info tf [ 0] jwt-server-5548445d89-vzgjj Pending (Pending) 2025-08-04T08:37:35.020792Z info klog Waiting for caches to sync controller=echo 2025-08-04T08:37:35.065010Z info klog Waiting for caches to sync controller=echo 2025-08-04T08:37:35.088245Z info klog Waiting for caches to sync controller=echo 2025-08-04T08:37:35.122050Z info klog Caches are synced controller=echo 2025-08-04T08:37:35.122819Z info klog Waiting for caches to sync controller=echo 2025-08-04T08:37:35.122817Z info klog Waiting for caches to sync controller=echo 2025-08-04T08:37:35.122867Z info klog Waiting for caches to sync controller=echo 2025-08-04T08:37:35.128331Z info klog Waiting for caches to sync controller=echo 2025-08-04T08:37:35.130652Z info klog Waiting for caches to sync controller=echo 2025-08-04T08:37:35.134948Z info klog Waiting for caches to sync controller=echo 2025-08-04T08:37:35.150603Z info tf Checking pods ready... 2025-08-04T08:37:35.150636Z info tf Checking pods ready... 2025-08-04T08:37:35.165460Z info klog Caches are synced controller=echo 2025-08-04T08:37:35.189255Z info klog Caches are synced controller=echo 2025-08-04T08:37:35.223301Z info klog Caches are synced controller=echo 2025-08-04T08:37:35.223361Z info klog Caches are synced controller=echo 2025-08-04T08:37:35.223343Z info klog Caches are synced controller=echo 2025-08-04T08:37:35.229288Z info klog Caches are synced controller=echo 2025-08-04T08:37:35.231791Z info klog Caches are synced controller=echo 2025-08-04T08:37:35.487311Z info tf [ 0] jwt-server-5548445d89-vzgjj Pending (Pending) 2025-08-04T08:37:35.535499Z info klog Caches are synced controller=echo 2025-08-04T08:37:36.287897Z info tf Checking pods ready... 2025-08-04T08:37:36.288030Z info tf Checking pods ready... 2025-08-04T08:37:36.473169Z info tf [ 0] jwt-server-5548445d89-vzgjj Pending (Pending) 2025-08-04T08:37:38.074074Z info tf Checking pods ready... 2025-08-04T08:37:38.074128Z info tf Checking pods ready... 2025-08-04T08:37:38.079714Z info tf [ 0] jwt-server-5548445d89-vzgjj Pending (Pending) 2025-08-04T08:37:41.280761Z info tf Checking pods ready... 2025-08-04T08:37:41.280814Z info tf Checking pods ready... 2025-08-04T08:37:41.290038Z info tf [ 0] jwt-server-5548445d89-vzgjj Pending (Pending) 2025-08-04T08:37:41.483918Z info tf patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true extensionProviders: - envoyExtAuthzHttp: headersToDownstreamOnDeny: - x-ext-authz-* headersToUpstreamOnAllow: - x-ext-authz-* includeAdditionalHeadersInCheck: x-ext-authz-additional-header-new: additional-header-new-value x-ext-authz-additional-header-override: additional-header-override-value includeRequestHeadersInCheck: - x-ext-authz port: 8000 service: ext-authz.servers.svc.cluster.local name: ext-authz-http - envoyExtAuthzGrpc: port: 9000 service: ext-authz.servers.svc.cluster.local name: ext-authz-grpc rootNamespace: istio-system trustDomain: cluster.local 2025-08-04T08:37:41.483966Z info tf === SUCCEEDED: Deploy authz server in 7.029684267s === 2025-08-04T08:37:44.490757Z info tf Checking pods ready... 2025-08-04T08:37:44.490927Z info tf Checking pods ready... 2025-08-04T08:37:44.496505Z info tf [ 0] jwt-server-5548445d89-vzgjj Pending (Pending) 2025-08-04T08:37:47.697536Z info tf Checking pods ready... 2025-08-04T08:37:47.697607Z info tf Checking pods ready... 2025-08-04T08:37:47.702353Z info tf [ 0] jwt-server-5548445d89-vzgjj Running (container not ready: 'istio-proxy') 2025-08-04T08:37:50.902884Z info tf Checking pods ready... 2025-08-04T08:37:50.902938Z info tf Checking pods ready... 2025-08-04T08:37:50.907641Z info tf [ 0] jwt-server-5548445d89-vzgjj Running (Ready) 2025-08-04T08:37:50.912182Z info tf === SUCCEEDED: Deploy JWT server in 16.457888543s === 2025-08-04T08:37:56.248616Z info tf === SUCCEEDED: Deploy echo instances in 21.654328043s === 2025-08-04T08:37:56.283323Z info tf === DONE: Setup: 'security_policy_attachment_only' (21.856376498s) === 2025-08-04T08:37:56.283432Z info tf === BEGIN: Test Run: 'security_policy_attachment_only' === PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_without_token (19.90s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-1_token (0.09s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_sub-1_token_due_to_ignored_RequestAuthentication (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_sub-2_token (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_expired_token (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-1_token_on_any.com (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-2_token_on_any.com (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_without_token_on_any.com (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_token_on_other_host (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_healthz (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b (20.16s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only (20.24s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication (20.66s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/allow_with_sub-1_token (0.08s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_without_token (0.03s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_based_on_unacceptable_HTTP_method (0.04s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_based_on_unacceptable_HTTP_path (0.02s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b (0.27s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only (0.35s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy (0.64s) 2025-08-04T08:38:17.579114Z info tf === DONE: Test Run: 'security_policy_attachment_only' === 2025-08-04T08:38:17.579160Z info tf === Suite "security_policy_attachment_only" run time: 43.152255172s === 2025-08-04T08:38:17.579184Z info tf Wrote trace to /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts/trace.yaml 2025-08-04T08:38:17.593148Z info tf cleanup patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true rootNamespace: istio-system trustDomain: cluster.local 2025-08-04T08:38:17.791592Z info tf cleanup patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true rootNamespace: istio-system trustDomain: cluster.local 2025-08-04T08:38:17.798220Z info tf === BEGIN: Cleanup Istio [Suite=security_policy_attachment_only] === 2025-08-04T08:38:17.798298Z info tf === SUCCEEDED: Cleanup Istio in 60.871µs [Suite=security_policy_attachment_only] === PASS tests/integration/security/policy_attachment_only DONE 20 tests in 56.731s exec: go version