exec: [go test -json -tags=integ -timeout 180m ./tests/integration/security/policy_attachment_only -args -istio.test.skipWorkloads=tproxy,vm -istio.test.openshift -istio.test.kube.helm.values=global.platform=openshift -istio.test.istio.enableCNI=true -istio.test.ci=true -istio.test.env=kube -istio.test.kube.deploy=false -istio.test.stableNamespaces=true -istio.test.kube.deployGatewayAPI=false -istio.test.gatewayConformance.maxTimeToConsistency=180s -istio.test.work_dir=/home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts] go test pid: 3487725 2025-12-09T11:00:24.249351Z warn unable to resolve TARGET_OUT. Dir /root/anurag/ossm3.x/istio-integration-test/istio-integration-3.1.4/istio/out/linux_ppc64le does not exist 2025-12-09T11:00:24.249408Z warn unable to resolve LOCAL_OUT. Dir /root/anurag/ossm3.x/istio-integration-test/istio-integration-3.1.4/istio/out/linux_ppc64le does not exist 2025-12-09T11:00:24.282850Z info tf === Test Framework Settings === 2025-12-09T11:00:24.282941Z info tf TestID: security_policy_attachment_only RunID: d9eac2c5-0adb-45ca-927d-8607038071a3 NoCleanup: false BaseDir: /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts Selector: FailOnDeprecation: false CIMode: true Retries: 0 StableNamespaces: true Revision: SkipWorkloads [tproxy vm] Compatibility: false Revisions: Hub: quay.io/maistra Tag: ibm-p Variant: PullPolicy: Always PullSecret: MaxDumps: 10 HelmRepo: https://istio-release.storage.googleapis.com/charts IPFamilies: [] GatewayConformanceStandardOnly: false GatewayConformanceAllowCRDsMismatch: false 2025-12-09T11:00:24.282951Z info tf =============================== 2025-12-09T11:00:24.283323Z info tf Test run dir: /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts/security-policy-attachment-only- 2025-12-09T11:00:24.283384Z info tf Test Framework Kubernetes environment Settings: Kubeconfigs: [] LoadBalancerSupported: true MCSControllerEnabled: false ControlPlaneTopology: map[] NetworkTopology: map[] ConfigTopology: map[] 2025-12-09T11:00:24.283405Z info tf Flags istio.test.kube.config and istio.test.kube.topology not specified. 2025-12-09T11:00:24.283425Z info tf Using KubeConfigs: [/root/upi/cC/auth/kubeconfig]. 2025-12-09T11:00:24.283436Z info tf === BEGIN: Building clusters === 2025-12-09T11:00:24.287442Z info tf Built Cluster: Name: cluster-0 StableName: primary-0 PrimaryCluster: cluster-0 ConfigCluster: cluster-0 Network: HTTPProxy: ProxyKubectlOnly: false Filename: /root/upi/cC/auth/kubeconfig 2025-12-09T11:00:24.287452Z info tf === DONE: Building clusters === 2025-12-09T11:00:24.287476Z info tf === BEGIN: Setup: 'security_policy_attachment_only' === 2025-12-09T11:00:24.287503Z info tf === BEGIN: Deploy Istio [Suite=security_policy_attachment_only] === 2025-12-09T11:00:24.287509Z info tf === Istio Component Config === 2025-12-09T11:00:24.287539Z info tf SystemNamespace: istio-system TelemetryNamespace: istio-system DeployIstio: false DeployEastWestGW: true Values: map[global.hub:quay.io/maistra global.imagePullPolicy:Always global.platform:openshift global.tag:ibm-p global.variant:] PrimaryClusterIOPFile: tests/integration/iop-integration-test-defaults.yaml ConfigClusterIOPFile: tests/integration/iop-integration-test-defaults.yaml RemoteClusterIOPFile: tests/integration/iop-remote-integration-test-defaults.yaml BaseIOPFile: tests/integration/base.yaml SkipWaitForValidationWebhook: false DumpKubernetesManifests: false IstiodlessRemotes: true OperatorOptions: map[] EnableCNI: true IngressGatewayServiceName: IngressGatewayServiceNamespace: IngressGatewayIstioLabel: EgressGatewayServiceName: istio-egressgateway EgressGatewayServiceNamespace: istio-system EgressGatewayIstioLabel: egressgateway SharedMeshConfigName: ControlPlaneInstaller: 2025-12-09T11:00:24.287544Z info tf ================================ 2025-12-09T11:00:24.290585Z info tf skipping deployment as specified in the config 2025-12-09T11:00:24.290600Z info tf === SUCCEEDED: Deploy Istio in 3.092325ms [Suite=security_policy_attachment_only]=== 2025-12-09T11:00:24.290639Z info tf === BEGIN: Create namespace servers === 2025-12-09T11:00:24.290676Z info tf === BEGIN: Create namespace echo1 === 2025-12-09T11:00:24.307279Z info tf === SUCCEEDED: Create namespace servers in 16.651867ms === 2025-12-09T11:00:24.313935Z info tf === SUCCEEDED: Create namespace echo1 in 23.301224ms === 2025-12-09T11:00:24.314012Z info tf === BEGIN: Deploy local authz server (ns=echo1) === 2025-12-09T11:00:24.314010Z info tf === BEGIN: Deploy authz server === 2025-12-09T11:00:24.314065Z info tf === BEGIN: Create namespace external === 2025-12-09T11:00:24.314055Z info tf === BEGIN: Deploy JWT server === 2025-12-09T11:00:24.351019Z info tf === SUCCEEDED: Create namespace external in 36.955694ms === 2025-12-09T11:00:24.353474Z info tf patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true extensionProviders: - envoyExtAuthzHttp: headersToDownstreamOnDeny: - x-ext-authz-* headersToUpstreamOnAllow: - x-ext-authz-* includeAdditionalHeadersInCheck: x-ext-authz-additional-header-new: additional-header-new-value x-ext-authz-additional-header-override: additional-header-override-value includeRequestHeadersInCheck: - x-ext-authz port: 8000 service: ext-authz-http.echo1.local name: ext-authz-http-echo1-local - envoyExtAuthzGrpc: port: 9000 service: ext-authz-grpc.echo1.local name: ext-authz-grpc-echo1-local rootNamespace: istio-system trustDomain: cluster.local 2025-12-09T11:00:24.388762Z info tf Checking pods ready... 2025-12-09T11:00:24.388861Z info tf Checking pods ready... 2025-12-09T11:00:24.397733Z info tf [ 0] jwt-server-5548445d89-nl6fh Running (Ready) 2025-12-09T11:00:24.413821Z info tf === SUCCEEDED: Deploy local authz server (ns=echo1) in 99.808809ms === 2025-12-09T11:00:24.416414Z info klog Warning: v1 Endpoints is deprecated in v1.33+; use discovery.k8s.io/v1 EndpointSlice 2025-12-09T11:00:24.416567Z info tf === SUCCEEDED: Deploy JWT server in 102.536474ms === 2025-12-09T11:00:24.417729Z info klog Warning: v1 Endpoints is deprecated in v1.33+; use discovery.k8s.io/v1 EndpointSlice 2025-12-09T11:00:24.469183Z info tf patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true extensionProviders: - envoyExtAuthzHttp: headersToDownstreamOnDeny: - x-ext-authz-* headersToUpstreamOnAllow: - x-ext-authz-* includeAdditionalHeadersInCheck: x-ext-authz-additional-header-new: additional-header-new-value x-ext-authz-additional-header-override: additional-header-override-value includeRequestHeadersInCheck: - x-ext-authz port: 8000 service: ext-authz-http.echo1.local name: ext-authz-http-echo1-local - envoyExtAuthzGrpc: port: 9000 service: ext-authz-grpc.echo1.local name: ext-authz-grpc-echo1-local - envoyExtAuthzHttp: headersToDownstreamOnDeny: - x-ext-authz-* headersToUpstreamOnAllow: - x-ext-authz-* includeAdditionalHeadersInCheck: x-ext-authz-additional-header-new: additional-header-new-value x-ext-authz-additional-header-override: additional-header-override-value includeRequestHeadersInCheck: - x-ext-authz port: 8000 service: ext-authz.servers.svc.cluster.local name: ext-authz-http - envoyExtAuthzGrpc: port: 9000 service: ext-authz.servers.svc.cluster.local name: ext-authz-grpc rootNamespace: istio-system trustDomain: cluster.local 2025-12-09T11:00:24.469308Z info tf === SUCCEEDED: Deploy authz server in 155.313142ms === 2025-12-09T11:00:24.518967Z info tf === BEGIN: Deploy echo instances === 2025-12-09T11:00:25.187373Z info klog Waiting for caches to sync controller=echo 2025-12-09T11:00:25.221370Z info klog Waiting for caches to sync controller=echo 2025-12-09T11:00:25.268610Z info klog Waiting for caches to sync controller=echo 2025-12-09T11:00:25.287944Z info klog Caches are synced controller=echo 2025-12-09T11:00:25.293999Z info klog Waiting for caches to sync controller=echo 2025-12-09T11:00:25.294377Z info klog Waiting for caches to sync controller=echo 2025-12-09T11:00:25.303269Z info klog Waiting for caches to sync controller=echo 2025-12-09T11:00:25.307940Z info klog Waiting for caches to sync controller=echo 2025-12-09T11:00:25.309244Z info klog Waiting for caches to sync controller=echo 2025-12-09T11:00:25.322313Z info klog Caches are synced controller=echo 2025-12-09T11:00:25.354486Z info klog Waiting for caches to sync controller=echo 2025-12-09T11:00:25.368763Z info klog Caches are synced controller=echo 2025-12-09T11:00:25.394420Z info klog Caches are synced controller=echo 2025-12-09T11:00:25.394585Z info klog Caches are synced controller=echo 2025-12-09T11:00:25.403960Z info klog Caches are synced controller=echo 2025-12-09T11:00:25.408512Z info klog Caches are synced controller=echo 2025-12-09T11:00:25.409473Z info klog Caches are synced controller=echo 2025-12-09T11:00:25.455640Z info klog Caches are synced controller=echo 2025-12-09T11:00:34.962647Z info tf === SUCCEEDED: Deploy echo instances in 10.443659351s === 2025-12-09T11:00:34.998189Z info tf === DONE: Setup: 'security_policy_attachment_only' (10.710695727s) === 2025-12-09T11:00:34.998231Z info tf === BEGIN: Test Run: 'security_policy_attachment_only' === PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_without_token (5.17s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-1_token (0.05s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_sub-1_token_due_to_ignored_RequestAuthentication (0.23s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_sub-2_token (0.06s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_expired_token (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-1_token_on_any.com (0.05s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-2_token_on_any.com (0.11s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_without_token_on_any.com (0.06s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_token_on_other_host (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_healthz (0.02s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b (5.79s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only (6.17s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication (11.62s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/allow_with_sub-1_token (1.09s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_without_token (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_based_on_unacceptable_HTTP_method (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_based_on_unacceptable_HTTP_path (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b (1.25s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only (1.39s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy (3.75s) 2025-12-09T11:00:50.367231Z info tf === DONE: Test Run: 'security_policy_attachment_only' === 2025-12-09T11:00:50.367273Z info tf === Suite "security_policy_attachment_only" run time: 26.079800273s === 2025-12-09T11:00:50.367293Z info tf Wrote trace to /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts/trace.yaml 2025-12-09T11:00:50.406089Z info tf cleanup patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true extensionProviders: - envoyExtAuthzHttp: headersToDownstreamOnDeny: - x-ext-authz-* headersToUpstreamOnAllow: - x-ext-authz-* includeAdditionalHeadersInCheck: x-ext-authz-additional-header-new: additional-header-new-value x-ext-authz-additional-header-override: additional-header-override-value includeRequestHeadersInCheck: - x-ext-authz port: 8000 service: ext-authz-http.echo1.local name: ext-authz-http-echo1-local - envoyExtAuthzGrpc: port: 9000 service: ext-authz-grpc.echo1.local name: ext-authz-grpc-echo1-local rootNamespace: istio-system trustDomain: cluster.local 2025-12-09T11:00:50.726228Z info tf cleanup patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true rootNamespace: istio-system trustDomain: cluster.local 2025-12-09T11:00:50.753218Z info tf === BEGIN: Cleanup Istio [Suite=security_policy_attachment_only] === 2025-12-09T11:00:50.753281Z info tf === SUCCEEDED: Cleanup Istio in 51.223µs [Suite=security_policy_attachment_only] === PASS tests/integration/security/policy_attachment_only DONE 20 tests in 26.539s exec: go version