exec: [go test -json -tags=integ -timeout 180m ./tests/integration/security/policy_attachment_only -args -istio.test.skipWorkloads=tproxy,vm -istio.test.openshift -istio.test.kube.helm.values=global.platform=openshift -istio.test.istio.enableCNI=true -istio.test.ci=true -istio.test.env=kube -istio.test.kube.deploy=false -istio.test.stableNamespaces=true -istio.test.kube.deployGatewayAPI=false -istio.test.gatewayConformance.maxTimeToConsistency=180s -istio.test.work_dir=/home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts] go test pid: 400832 2025-12-09T16:32:47.580713Z warn unable to resolve TARGET_OUT. Dir /root/anurag/ossm3/istio/out/linux_ppc64le does not exist 2025-12-09T16:32:47.580769Z warn unable to resolve LOCAL_OUT. Dir /root/anurag/ossm3/istio/out/linux_ppc64le does not exist 2025-12-09T16:32:47.612703Z info tf === Test Framework Settings === 2025-12-09T16:32:47.612794Z info tf TestID: security_policy_attachment_only RunID: 837d8abe-9e10-4082-a941-1159e978b3f6 NoCleanup: false BaseDir: /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts Selector: FailOnDeprecation: false CIMode: true Retries: 0 StableNamespaces: true Revision: SkipWorkloads [tproxy vm] Compatibility: false Revisions: Hub: quay.io/maistra Tag: ibm-p Variant: PullPolicy: Always PullSecret: MaxDumps: 10 HelmRepo: https://istio-release.storage.googleapis.com/charts IPFamilies: [] GatewayConformanceStandardOnly: false GatewayConformanceAllowCRDsMismatch: false 2025-12-09T16:32:47.612799Z info tf =============================== 2025-12-09T16:32:47.614124Z info tf Test run dir: /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts/security-policy-attachment-only- 2025-12-09T16:32:47.614440Z info tf Test Framework Kubernetes environment Settings: Kubeconfigs: [] LoadBalancerSupported: true MCSControllerEnabled: false ControlPlaneTopology: map[] NetworkTopology: map[] ConfigTopology: map[] 2025-12-09T16:32:47.614453Z info tf Flags istio.test.kube.config and istio.test.kube.topology not specified. 2025-12-09T16:32:47.615516Z info tf Using KubeConfigs: [/root/upi/cA/auth/kubeconfig]. 2025-12-09T16:32:47.615527Z info tf === BEGIN: Building clusters === 2025-12-09T16:32:47.619535Z info tf Built Cluster: Name: cluster-0 StableName: primary-0 PrimaryCluster: cluster-0 ConfigCluster: cluster-0 Network: HTTPProxy: ProxyKubectlOnly: false Filename: /root/upi/cA/auth/kubeconfig 2025-12-09T16:32:47.619544Z info tf === DONE: Building clusters === 2025-12-09T16:32:47.619564Z info tf === BEGIN: Setup: 'security_policy_attachment_only' === 2025-12-09T16:32:47.619845Z info tf === BEGIN: Deploy Istio [Suite=security_policy_attachment_only] === 2025-12-09T16:32:47.619854Z info tf === Istio Component Config === 2025-12-09T16:32:47.619883Z info tf SystemNamespace: istio-system TelemetryNamespace: istio-system DeployIstio: false DeployEastWestGW: true Values: map[global.hub:quay.io/maistra global.imagePullPolicy:Always global.platform:openshift global.tag:ibm-p global.variant:] PrimaryClusterIOPFile: tests/integration/iop-integration-test-defaults.yaml ConfigClusterIOPFile: tests/integration/iop-integration-test-defaults.yaml RemoteClusterIOPFile: tests/integration/iop-remote-integration-test-defaults.yaml BaseIOPFile: tests/integration/base.yaml SkipWaitForValidationWebhook: false DumpKubernetesManifests: false IstiodlessRemotes: true OperatorOptions: map[] EnableCNI: true IngressGatewayServiceName: IngressGatewayServiceNamespace: IngressGatewayIstioLabel: EgressGatewayServiceName: istio-egressgateway EgressGatewayServiceNamespace: istio-system EgressGatewayIstioLabel: egressgateway SharedMeshConfigName: ControlPlaneInstaller: 2025-12-09T16:32:47.619887Z info tf ================================ 2025-12-09T16:32:47.625236Z info tf skipping deployment as specified in the config 2025-12-09T16:32:47.625303Z info tf === SUCCEEDED: Deploy Istio in 5.449636ms [Suite=security_policy_attachment_only]=== 2025-12-09T16:32:47.625380Z info tf === BEGIN: Create namespace servers === 2025-12-09T16:32:47.625402Z info tf === BEGIN: Create namespace echo1 === 2025-12-09T16:32:47.661672Z info tf === SUCCEEDED: Create namespace servers in 36.317852ms === 2025-12-09T16:32:47.666361Z info tf === SUCCEEDED: Create namespace echo1 in 40.998452ms === 2025-12-09T16:32:47.666435Z info tf === BEGIN: Deploy authz server === 2025-12-09T16:32:47.666450Z info tf === BEGIN: Deploy local authz server (ns=echo1) === 2025-12-09T16:32:47.666493Z info tf === BEGIN: Create namespace external === 2025-12-09T16:32:47.666589Z info tf === BEGIN: Deploy JWT server === 2025-12-09T16:32:47.704641Z info tf patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true extensionProviders: - envoyExtAuthzHttp: headersToDownstreamOnDeny: - x-ext-authz-* headersToUpstreamOnAllow: - x-ext-authz-* includeAdditionalHeadersInCheck: x-ext-authz-additional-header-new: additional-header-new-value x-ext-authz-additional-header-override: additional-header-override-value includeRequestHeadersInCheck: - x-ext-authz port: 8000 service: ext-authz-http.echo1.local name: ext-authz-http-echo1-local - envoyExtAuthzGrpc: port: 9000 service: ext-authz-grpc.echo1.local name: ext-authz-grpc-echo1-local rootNamespace: istio-system trustDomain: cluster.local 2025-12-09T16:32:47.720424Z info tf === SUCCEEDED: Create namespace external in 53.92874ms === 2025-12-09T16:32:47.822821Z info tf === SUCCEEDED: Deploy local authz server (ns=echo1) in 156.385278ms === 2025-12-09T16:32:47.852674Z info tf Checking pods ready... 2025-12-09T16:32:47.852707Z info tf Checking pods ready... 2025-12-09T16:32:47.901793Z info tf No pods found... 2025-12-09T16:32:47.912144Z info klog Warning: v1 Endpoints is deprecated in v1.33+; use discovery.k8s.io/v1 EndpointSlice 2025-12-09T16:32:47.971594Z info tf === BEGIN: Deploy echo instances === 2025-12-09T16:32:48.102881Z info tf Checking pods ready... 2025-12-09T16:32:48.102996Z info tf Checking pods ready... 2025-12-09T16:32:48.138115Z info klog Warning: v1 Endpoints is deprecated in v1.33+; use discovery.k8s.io/v1 EndpointSlice 2025-12-09T16:32:48.152553Z info tf [ 0] jwt-server-5548445d89-7l2hm Pending (Pending) 2025-12-09T16:32:48.553050Z info tf Checking pods ready... 2025-12-09T16:32:48.553115Z info tf Checking pods ready... 2025-12-09T16:32:48.564379Z info klog Warning: v1 Endpoints is deprecated in v1.33+; use discovery.k8s.io/v1 EndpointSlice 2025-12-09T16:32:48.616700Z info tf [ 0] jwt-server-5548445d89-7l2hm Pending (Pending) 2025-12-09T16:32:48.843921Z info klog Waiting for caches to sync controller=echo 2025-12-09T16:32:48.876079Z info sync complete name=pod controller attempt=5 time=32.077303ms 2025-12-09T16:32:48.889309Z info klog Waiting for caches to sync controller=echo 2025-12-09T16:32:48.895342Z info klog Waiting for caches to sync controller=echo 2025-12-09T16:32:48.896703Z info sync complete name=pod controller attempt=3 time=7.318612ms 2025-12-09T16:32:48.898243Z info klog Waiting for caches to sync controller=echo 2025-12-09T16:32:48.902841Z info sync complete name=pod controller attempt=3 time=7.441759ms 2025-12-09T16:32:48.914271Z info sync complete name=pod controller attempt=4 time=16.005802ms 2025-12-09T16:32:48.938783Z info klog Waiting for caches to sync controller=echo 2025-12-09T16:32:48.944838Z info klog Caches are synced controller=echo 2025-12-09T16:32:48.945110Z info sync complete name=pod controller attempt=3 time=6.276891ms 2025-12-09T16:32:48.946605Z info klog Waiting for caches to sync controller=echo 2025-12-09T16:32:48.948698Z info sync complete name=pod controller attempt=2 time=2.057694ms 2025-12-09T16:32:48.950586Z info klog Waiting for caches to sync controller=echo 2025-12-09T16:32:48.953146Z info sync complete name=pod controller attempt=2 time=2.53203ms 2025-12-09T16:32:48.957539Z info klog Waiting for caches to sync controller=echo 2025-12-09T16:32:48.960891Z info klog Waiting for caches to sync controller=echo 2025-12-09T16:32:48.964049Z info sync complete name=pod controller attempt=3 time=6.484781ms 2025-12-09T16:32:48.977789Z info sync complete name=pod controller attempt=4 time=16.844897ms 2025-12-09T16:32:48.990414Z info klog Caches are synced controller=echo 2025-12-09T16:32:48.996158Z info klog Caches are synced controller=echo 2025-12-09T16:32:48.998686Z info klog Caches are synced controller=echo 2025-12-09T16:32:49.038919Z info klog Caches are synced controller=echo 2025-12-09T16:32:49.046770Z info klog Caches are synced controller=echo 2025-12-09T16:32:49.051461Z info klog Caches are synced controller=echo 2025-12-09T16:32:49.058207Z info klog Caches are synced controller=echo 2025-12-09T16:32:49.061710Z info klog Caches are synced controller=echo 2025-12-09T16:32:49.395391Z info klog Warning: v1 Endpoints is deprecated in v1.33+; use discovery.k8s.io/v1 EndpointSlice 2025-12-09T16:32:49.417168Z info tf Checking pods ready... 2025-12-09T16:32:49.417214Z info tf Checking pods ready... 2025-12-09T16:32:49.437162Z info tf [ 0] jwt-server-5548445d89-7l2hm Pending (Pending) 2025-12-09T16:32:51.003737Z info klog Warning: v1 Endpoints is deprecated in v1.33+; use discovery.k8s.io/v1 EndpointSlice 2025-12-09T16:32:51.037622Z info tf Checking pods ready... 2025-12-09T16:32:51.037737Z info tf Checking pods ready... 2025-12-09T16:32:51.042365Z info tf [ 0] jwt-server-5548445d89-7l2hm Pending (Pending) 2025-12-09T16:32:54.214666Z info klog Warning: v1 Endpoints is deprecated in v1.33+; use discovery.k8s.io/v1 EndpointSlice 2025-12-09T16:32:54.232491Z info tf patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true extensionProviders: - envoyExtAuthzHttp: headersToDownstreamOnDeny: - x-ext-authz-* headersToUpstreamOnAllow: - x-ext-authz-* includeAdditionalHeadersInCheck: x-ext-authz-additional-header-new: additional-header-new-value x-ext-authz-additional-header-override: additional-header-override-value includeRequestHeadersInCheck: - x-ext-authz port: 8000 service: ext-authz.servers.svc.cluster.local name: ext-authz-http - envoyExtAuthzGrpc: port: 9000 service: ext-authz.servers.svc.cluster.local name: ext-authz-grpc rootNamespace: istio-system trustDomain: cluster.local 2025-12-09T16:32:54.232522Z info tf === SUCCEEDED: Deploy authz server in 6.566102604s === 2025-12-09T16:32:54.242790Z info tf Checking pods ready... 2025-12-09T16:32:54.242816Z info tf Checking pods ready... 2025-12-09T16:32:54.253960Z info tf [ 0] jwt-server-5548445d89-7l2hm Running (Ready) 2025-12-09T16:32:54.267181Z info klog Warning: v1 Endpoints is deprecated in v1.33+; use discovery.k8s.io/v1 EndpointSlice 2025-12-09T16:32:54.267323Z info tf === SUCCEEDED: Deploy JWT server in 6.600863274s === 2025-12-09T16:33:04.969863Z info tf === SUCCEEDED: Deploy echo instances in 16.99826014s === 2025-12-09T16:33:05.004865Z info tf === DONE: Setup: 'security_policy_attachment_only' (17.385287467s) === 2025-12-09T16:33:05.004907Z info tf === BEGIN: Test Run: 'security_policy_attachment_only' === PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_without_token (5.16s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-1_token (0.04s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_sub-1_token_due_to_ignored_RequestAuthentication (0.02s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_sub-2_token (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_expired_token (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-1_token_on_any.com (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_with_sub-2_token_on_any.com (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_without_token_on_any.com (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/deny_with_token_on_other_host (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b/allow_healthz (0.02s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only/to_b (5.43s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication/gateway-authn-policy-attachment-only (5.58s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIRequestAuthentication (6.13s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/allow_with_sub-1_token (2.55s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_without_token (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_based_on_unacceptable_HTTP_method (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b/deny_based_on_unacceptable_HTTP_path (0.01s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only/to_b (2.67s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy/gateway-authz-policy-attachment-only (2.80s) PASS tests/integration/security/policy_attachment_only.TestGatewayAPIAuthorizationPolicy (3.12s) 2025-12-09T16:33:14.251870Z info tf === DONE: Test Run: 'security_policy_attachment_only' === 2025-12-09T16:33:14.251898Z info tf === Suite "security_policy_attachment_only" run time: 26.632337523s === 2025-12-09T16:33:14.251916Z info tf Wrote trace to /home/jenkins/workspace/sail/istio-integration-tests-suites/security-policy_attachment_only/artifacts/trace.yaml 2025-12-09T16:33:14.289641Z info tf cleanup patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true rootNamespace: istio-system trustDomain: cluster.local 2025-12-09T16:33:14.530182Z info tf cleanup patched cluster-0 meshconfig: defaultConfig: discoveryAddress: istiod.istio-system.svc:15012 gatewayTopology: numTrustedProxies: 1 defaultProviders: metrics: - prometheus enablePrometheusMerge: true rootNamespace: istio-system trustDomain: cluster.local 2025-12-09T16:33:14.617430Z info tf === BEGIN: Cleanup Istio [Suite=security_policy_attachment_only] === 2025-12-09T16:33:14.617482Z info tf === SUCCEEDED: Cleanup Istio in 44.303µs [Suite=security_policy_attachment_only] === PASS tests/integration/security/policy_attachment_only DONE 20 tests in 43.825s exec: go version