istio: Test Failure: security/tests/integration/certificateRotationTest

From: https://k8s-gubernator.appspot.com/build/istio-prow/pull/istio_istio/3913/istio-presubmit/6070/

I0302 22:34:20.343] 2018-03-02T22:34:20.341870Z	error	failed to create test namespace: failed to create a role (error: failed to create role (error: roles.rbac.authorization.k8s.io "istio-ca-role" is forbidden: attempt to grant extra privileges: [PolicyRule{Resources:["secrets"], APIGroups:["core"], Verbs:["create"]} PolicyRule{Resources:["secrets"], APIGroups:["core"], Verbs:["get"]} PolicyRule{Resources:["secrets"], APIGroups:["core"], Verbs:["watch"]} PolicyRule{Resources:["secrets"], APIGroups:["core"], Verbs:["list"]} PolicyRule{Resources:["secrets"], APIGroups:["core"], Verbs:["update"]} PolicyRule{Resources:["secrets"], APIGroups:[""], Verbs:["create"]} PolicyRule{Resources:["secrets"], APIGroups:[""], Verbs:["get"]} PolicyRule{Resources:["secrets"], APIGroups:[""], Verbs:["watch"]} PolicyRule{Resources:["secrets"], APIGroups:[""], Verbs:["list"]} PolicyRule{Resources:["secrets"], APIGroups:[""], Verbs:["update"]} PolicyRule{Resources:["serviceaccounts"], APIGroups:["core"], Verbs:["get"]} PolicyRule{Resources:["serviceaccounts"], APIGroups:["core"], Verbs:["watch"]} PolicyRule{Resources:["serviceaccounts"], APIGroups:["core"], Verbs:["list"]} PolicyRule{Resources:["services"], APIGroups:["core"], Verbs:["get"]} PolicyRule{Resources:["services"], APIGroups:["core"], Verbs:["watch"]} PolicyRule{Resources:["services"], APIGroups:["core"], Verbs:["list"]} PolicyRule{Resources:["pods"], APIGroups:["core"], Verbs:["get"]} PolicyRule{Resources:["pods"], APIGroups:["core"], Verbs:["watch"]} PolicyRule{Resources:["pods"], APIGroups:["core"], Verbs:["list"]} PolicyRule{Resources:["serviceaccounts"], APIGroups:[""], Verbs:["get"]} PolicyRule{Resources:["serviceaccounts"], APIGroups:[""], Verbs:["watch"]} PolicyRule{Resources:["serviceaccounts"], APIGroups:[""], Verbs:["list"]} PolicyRule{Resources:["services"], APIGroups:[""], Verbs:["get"]} PolicyRule{Resources:["services"], APIGroups:[""], Verbs:["watch"]} PolicyRule{Resources:["services"], APIGroups:[""], Verbs:["list"]} PolicyRule{Resources:["pods"], APIGroups:[""], Verbs:["get"]} PolicyRule{Resources:["pods"], APIGroups:[""], Verbs:["watch"]} PolicyRule{Resources:["pods"], APIGroups:[""], Verbs:["list"]}] user=&{istio-prow-test-job@istio-testing.iam.gserviceaccount.com  [system:authenticated] map[authenticator:[GKE]]} ownerrules=[PolicyRule{Resources:["selfsubjectaccessreviews" "selfsubjectrulesreviews"], APIGroups:["authorization.k8s.io"], Verbs:["create"]} PolicyRule{NonResourceURLs:["/api" "/api/*" "/apis" "/apis/*" "/healthz" "/swagger-2.0.0.pb-v1" "/swagger.json" "/swaggerapi" "/swaggerapi/*" "/version"], Verbs:["get"]}] ruleResolutionErrors=[]))
I0302 22:34:20.344] 2018-03-02T22:34:20.341877Z	error	test environment creation failure
I0302 22:34:20.344] FAIL	istio.io/istio/security/tests/integration/certificateRotationTest	2.535s
E0302 22:34:20.355] Build failed
I0302 22:34:20.355] process 509 exited with code 1 after 15.7m
E0302 22:34:20.355] FAIL: istio-presubmit

About this issue

  • Original URL
  • State: closed
  • Created 6 years ago
  • Reactions: 1
  • Comments: 15 (15 by maintainers)

Commits related to this issue

Most upvoted comments

@sebastienvas Yes, it is.