Log: /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/logs/security-context.log grep: warning: stray \ before - Warning: version difference between client (1.35) and server (1.31) exceeds the supported minor version skew of +/-1 Warning: version difference between client (1.35) and server (1.31) exceeds the supported minor version skew of +/-1 Warning: version difference between client (1.35) and server (1.31) exceeds the supported minor version skew of +/-1 + create_infra security-context-11319 + local ns=security-context-11319 + [[ 1 == 1 ]] + delete_crd + desc 'get and delete old CRDs and RBAC' + set +o xtrace ----------------------------------------------------------------------------------- get and delete old CRDs and RBAC ----------------------------------------------------------------------------------- + kubectl_bin delete -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/deploy/crd.yaml --ignore-not-found --wait=false ++ mktemp + local LAST_OUT=/tmp/tmp.B9OSsegG3X ++ mktemp + local LAST_ERR=/tmp/tmp.OsGniwLAJ6 + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl delete -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/deploy/crd.yaml --ignore-not-found --wait=false + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.B9OSsegG3X customresourcedefinition.apiextensions.k8s.io "perconaservermongodbbackups.psmdb.percona.com" deleted customresourcedefinition.apiextensions.k8s.io "perconaservermongodbrestores.psmdb.percona.com" deleted customresourcedefinition.apiextensions.k8s.io "perconaservermongodbs.psmdb.percona.com" deleted + cat /tmp/tmp.OsGniwLAJ6 + rm /tmp/tmp.B9OSsegG3X /tmp/tmp.OsGniwLAJ6 + return 0 ++ yq eval .metadata.name /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/deploy/crd.yaml ++ grep -v '\-\-\-' grep: warning: stray \ before - grep: warning: stray \ before - + for crd_name in $(yq eval '.metadata.name' "${src_dir}/deploy/crd.yaml" | grep -v '\-\-\-') + kubectl get perconaservermongodbbackups.psmdb.percona.com --all-namespaces -o wide + grep -v NAMESPACE + xargs -L 1 sh -xc 'kubectl patch perconaservermongodbbackups.psmdb.percona.com -n $0 $1 --type=merge -p "{\"metadata\":{\"finalizers\":[]}}"' No resources found + kubectl patch perconaservermongodbbackups.psmdb.percona.com -n sh --type=merge -p '{"metadata":{"finalizers":[]}}' error: resource(s) were provided, but no name was specified + : + kubectl_bin wait --for=delete crd perconaservermongodbbackups.psmdb.percona.com ++ mktemp + local LAST_OUT=/tmp/tmp.47cacmMDAA ++ mktemp + local LAST_ERR=/tmp/tmp.qC3TLO3wxG + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl wait --for=delete crd perconaservermongodbbackups.psmdb.percona.com + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.47cacmMDAA + cat /tmp/tmp.qC3TLO3wxG + rm /tmp/tmp.47cacmMDAA /tmp/tmp.qC3TLO3wxG + return 0 + for crd_name in $(yq eval '.metadata.name' "${src_dir}/deploy/crd.yaml" | grep -v '\-\-\-') + kubectl get perconaservermongodbrestores.psmdb.percona.com --all-namespaces -o wide + grep -v NAMESPACE + xargs -L 1 sh -xc 'kubectl patch perconaservermongodbrestores.psmdb.percona.com -n $0 $1 --type=merge -p "{\"metadata\":{\"finalizers\":[]}}"' error: the server doesn't have a resource type "perconaservermongodbrestores" + kubectl patch perconaservermongodbrestores.psmdb.percona.com -n sh --type=merge -p '{"metadata":{"finalizers":[]}}' error: the server doesn't have a resource type "perconaservermongodbrestores" + : + kubectl_bin wait --for=delete crd perconaservermongodbrestores.psmdb.percona.com ++ mktemp + local LAST_OUT=/tmp/tmp.S5IAeDhF6n ++ mktemp + local LAST_ERR=/tmp/tmp.0rUAwQR0Dg + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl wait --for=delete crd perconaservermongodbrestores.psmdb.percona.com + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.S5IAeDhF6n + cat /tmp/tmp.0rUAwQR0Dg + rm /tmp/tmp.S5IAeDhF6n /tmp/tmp.0rUAwQR0Dg + return 0 + for crd_name in $(yq eval '.metadata.name' "${src_dir}/deploy/crd.yaml" | grep -v '\-\-\-') + kubectl get perconaservermongodbs.psmdb.percona.com --all-namespaces -o wide + grep -v NAMESPACE + xargs -L 1 sh -xc 'kubectl patch perconaservermongodbs.psmdb.percona.com -n $0 $1 --type=merge -p "{\"metadata\":{\"finalizers\":[]}}"' error: the server doesn't have a resource type "perconaservermongodbs" + kubectl patch perconaservermongodbs.psmdb.percona.com -n sh --type=merge -p '{"metadata":{"finalizers":[]}}' error: the server doesn't have a resource type "perconaservermongodbs" + : + kubectl_bin wait --for=delete crd perconaservermongodbs.psmdb.percona.com ++ mktemp + local LAST_OUT=/tmp/tmp.tskyzrNIFP ++ mktemp + local LAST_ERR=/tmp/tmp.DvkUNMKzua + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl wait --for=delete crd perconaservermongodbs.psmdb.percona.com + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.tskyzrNIFP + cat /tmp/tmp.DvkUNMKzua + rm /tmp/tmp.tskyzrNIFP /tmp/tmp.DvkUNMKzua + return 0 + local rbac_yaml=rbac.yaml + '[' -n psmdb-operator ']' + rbac_yaml=cw-rbac.yaml + kubectl_bin delete -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/deploy/cw-rbac.yaml --ignore-not-found ++ mktemp + local LAST_OUT=/tmp/tmp.CBlFwJY3IB ++ mktemp + local LAST_ERR=/tmp/tmp.soI37bIlYs + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl delete -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/deploy/cw-rbac.yaml --ignore-not-found + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.CBlFwJY3IB clusterrole.rbac.authorization.k8s.io "percona-server-mongodb-operator" deleted clusterrolebinding.rbac.authorization.k8s.io "service-account-percona-server-mongodb-operator" deleted + cat /tmp/tmp.soI37bIlYs + rm /tmp/tmp.CBlFwJY3IB /tmp/tmp.soI37bIlYs + return 0 + check_crd_for_deletion PR-2152-4461031b + local git_tag=PR-2152-4461031b ++ curl -s https://raw.githubusercontent.com/percona/percona-server-mongodb-operator/PR-2152-4461031b/deploy/crd.yaml ++ yq eval .metadata.name ++ /usr/sbin/sed s/---//g ++ /usr/sbin/sed ':a;N;$!ba;s/\n/ /g' + for crd_name in $(curl -s https://raw.githubusercontent.com/percona/percona-server-mongodb-operator/${git_tag}/deploy/crd.yaml | yq eval '.metadata.name' | $sed 's/---//g' | $sed ':a;N;$!ba;s/\n/ /g') ++ kubectl_bin get crd/null -o 'jsonpath={.status.conditions[-1].type}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.OifKPHiAGC +++ mktemp ++ local LAST_ERR=/tmp/tmp.QtYylCIpNb ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get crd/null -o 'jsonpath={.status.conditions[-1].type}' ++ exit_status=1 ++ set -e ++ '[' 1 '!=' 0 -a -n 1 ']' ++ cat /tmp/tmp.OifKPHiAGC ++ cat /tmp/tmp.QtYylCIpNb Error from server (NotFound): customresourcedefinitions.apiextensions.k8s.io "null" not found ++ sleep 0 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get crd/null -o 'jsonpath={.status.conditions[-1].type}' ++ exit_status=1 ++ set -e ++ '[' 1 '!=' 0 -a -n 1 ']' ++ cat /tmp/tmp.OifKPHiAGC ++ cat /tmp/tmp.QtYylCIpNb Error from server (NotFound): customresourcedefinitions.apiextensions.k8s.io "null" not found ++ sleep 4 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get crd/null -o 'jsonpath={.status.conditions[-1].type}' ++ exit_status=1 ++ set -e ++ '[' 1 '!=' 0 -a -n 1 ']' ++ cat /tmp/tmp.OifKPHiAGC ++ cat /tmp/tmp.QtYylCIpNb Error from server (NotFound): customresourcedefinitions.apiextensions.k8s.io "null" not found ++ sleep 8 ++ cat /tmp/tmp.OifKPHiAGC ++ cat /tmp/tmp.QtYylCIpNb Error from server (NotFound): customresourcedefinitions.apiextensions.k8s.io "null" not found ++ rm /tmp/tmp.OifKPHiAGC /tmp/tmp.QtYylCIpNb ++ return 1 + [[ '' == \T\e\r\m\i\n\a\t\i\n\g ]] + '[' -n psmdb-operator ']' + create_namespace psmdb-operator + local namespace=psmdb-operator + local skip_clean_namespace= + [[ 1 == 1 ]] + [[ -z '' ]] + destroy_chaos_mesh ++ helm list --all-namespaces --filter chaos-mesh ++ tail -n1 ++ awk '-F ' '{print $2}' ++ sed s/NAMESPACE// + local chaos_mesh_ns= + desc 'destroy chaos-mesh' + set +o xtrace ----------------------------------------------------------------------------------- destroy chaos-mesh ----------------------------------------------------------------------------------- + '[' -n '' ']' ++ kubectl get MutatingWebhookConfiguration ++ grep chaos-mesh ++ awk '{print $1}' + timeout 30 kubectl delete MutatingWebhookConfiguration error: resource(s) were provided, but no name was specified + : ++ kubectl get ValidatingWebhookConfiguration ++ grep chaos-mesh ++ awk '{print $1}' + timeout 30 kubectl delete ValidatingWebhookConfiguration error: resource(s) were provided, but no name was specified + : ++ kubectl get ValidatingWebhookConfiguration ++ grep validate-auth ++ awk '{print $1}' + timeout 30 kubectl delete ValidatingWebhookConfiguration error: resource(s) were provided, but no name was specified + : ++ kubectl api-resources ++ grep chaos-mesh ++ awk '{print $1}' ++ kubectl get crd ++ grep chaos-mesh.org ++ awk '{print $1}' + timeout 30 kubectl delete crd error: resource(s) were provided, but no name was specified + : ++ kubectl get clusterrolebinding ++ grep chaos-mesh ++ awk '{print $1}' + timeout 30 kubectl delete clusterrolebinding error: resource(s) were provided, but no name was specified + : ++ kubectl get clusterrole ++ grep chaos-mesh ++ awk '{print $1}' + timeout 30 kubectl delete clusterrole error: resource(s) were provided, but no name was specified + : + desc 'cleaned up all old namespaces' + set +o xtrace ----------------------------------------------------------------------------------- cleaned up all old namespaces ----------------------------------------------------------------------------------- + kubectl_bin get ns + egrep -v '^kube-|^default|Terminating|psmdb-operator|openshift|^gke-|^gmp-|^NAME' + awk '{print$1}' + '[' -n '' ']' + desc 'cleaned up old namespaces psmdb-operator' + set +o xtrace + xargs kubectl delete ns ----------------------------------------------------------------------------------- cleaned up old namespaces psmdb-operator ----------------------------------------------------------------------------------- + kubectl_bin delete namespace psmdb-operator --ignore-not-found ++ mktemp ++ mktemp egrep: warning: egrep is obsolescent; using grep -E + local LAST_OUT=/tmp/tmp.ZzUYRwqIic + local LAST_OUT=/tmp/tmp.BxH7ghsuna ++ mktemp ++ mktemp + local LAST_ERR=/tmp/tmp.lEKHsaYBvX + local exit_status=0 + local timeout=4 ++ seq 0 2 + local LAST_ERR=/tmp/tmp.vGkOL63419 + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl get ns + for i in $(seq 0 2) + set +e + kubectl delete namespace psmdb-operator --ignore-not-found + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.ZzUYRwqIic + cat /tmp/tmp.lEKHsaYBvX + rm /tmp/tmp.ZzUYRwqIic /tmp/tmp.lEKHsaYBvX + return 0 namespace "security-context-21157" deleted + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.BxH7ghsuna namespace "psmdb-operator" deleted + cat /tmp/tmp.vGkOL63419 + rm /tmp/tmp.BxH7ghsuna /tmp/tmp.vGkOL63419 + return 0 + kubectl_bin wait --for=delete namespace psmdb-operator ++ mktemp + local LAST_OUT=/tmp/tmp.6u7AmOceDx ++ mktemp + local LAST_ERR=/tmp/tmp.IeuZHYgI5k + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl wait --for=delete namespace psmdb-operator + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.6u7AmOceDx + cat /tmp/tmp.IeuZHYgI5k + rm /tmp/tmp.6u7AmOceDx /tmp/tmp.IeuZHYgI5k + return 0 + desc 'create namespace psmdb-operator' + set +o xtrace ----------------------------------------------------------------------------------- create namespace psmdb-operator ----------------------------------------------------------------------------------- + kubectl_bin create namespace psmdb-operator ++ mktemp + local LAST_OUT=/tmp/tmp.JRMHch1Ll4 ++ mktemp + local LAST_ERR=/tmp/tmp.OzXeFIObKq + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl create namespace psmdb-operator + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.JRMHch1Ll4 namespace/psmdb-operator created + cat /tmp/tmp.OzXeFIObKq + rm /tmp/tmp.JRMHch1Ll4 /tmp/tmp.OzXeFIObKq + return 0 + set_kube_ctx psmdb-operator + local namespace=psmdb-operator ++ kubectl_bin config current-context +++ mktemp ++ local LAST_OUT=/tmp/tmp.ow62SnXUly +++ mktemp ++ local LAST_ERR=/tmp/tmp.IEjWW1zFqD ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl config current-context ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.ow62SnXUly ++ cat /tmp/tmp.IEjWW1zFqD ++ rm /tmp/tmp.ow62SnXUly /tmp/tmp.IEjWW1zFqD ++ return 0 + kubectl_bin config set-context gke_cloud-dev-112233_us-central1-a_jen-psmdb-2152-4461031b-2-cluster10 --namespace=psmdb-operator ++ mktemp + local LAST_OUT=/tmp/tmp.i2U2bvs2XT ++ mktemp + local LAST_ERR=/tmp/tmp.bmMIafjRXz + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl config set-context gke_cloud-dev-112233_us-central1-a_jen-psmdb-2152-4461031b-2-cluster10 --namespace=psmdb-operator + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.i2U2bvs2XT Context "gke_cloud-dev-112233_us-central1-a_jen-psmdb-2152-4461031b-2-cluster10" modified. + cat /tmp/tmp.bmMIafjRXz + rm /tmp/tmp.i2U2bvs2XT /tmp/tmp.bmMIafjRXz + return 0 + deploy_operator + desc 'start PSMDB operator: perconalab/percona-server-mongodb-operator:PR-2152-4461031b' + set +o xtrace ----------------------------------------------------------------------------------- start PSMDB operator: perconalab/percona-server-mongodb-operator:PR-2152-4461031b ----------------------------------------------------------------------------------- + local cr_file + '[' -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/conf/crd.yaml ']' + cr_file=/mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/deploy/crd.yaml + kubectl_bin apply --server-side --force-conflicts -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/deploy/crd.yaml ++ mktemp + local LAST_OUT=/tmp/tmp.UnobZY42Is ++ mktemp + local LAST_ERR=/tmp/tmp.GGr6QUXiXK + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl apply --server-side --force-conflicts -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/deploy/crd.yaml + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.UnobZY42Is customresourcedefinition.apiextensions.k8s.io/perconaservermongodbbackups.psmdb.percona.com serverside-applied customresourcedefinition.apiextensions.k8s.io/perconaservermongodbrestores.psmdb.percona.com serverside-applied customresourcedefinition.apiextensions.k8s.io/perconaservermongodbs.psmdb.percona.com serverside-applied + cat /tmp/tmp.GGr6QUXiXK + rm /tmp/tmp.UnobZY42Is /tmp/tmp.GGr6QUXiXK + return 0 + '[' -n psmdb-operator ']' + apply_rbac cw-rbac + local operator_namespace=psmdb-operator + local rbac=cw-rbac + cat /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/deploy/cw-rbac.yaml + sed -e 's^namespace: .*^namespace: psmdb-operator^' + kubectl_bin apply -n psmdb-operator -f - ++ mktemp + local LAST_OUT=/tmp/tmp.zvBaPnpKHf ++ mktemp + local LAST_ERR=/tmp/tmp.wUoJIvfzzI + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl apply -n psmdb-operator -f - + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.zvBaPnpKHf clusterrole.rbac.authorization.k8s.io/percona-server-mongodb-operator created serviceaccount/percona-server-mongodb-operator created clusterrolebinding.rbac.authorization.k8s.io/service-account-percona-server-mongodb-operator created + cat /tmp/tmp.wUoJIvfzzI + rm /tmp/tmp.zvBaPnpKHf /tmp/tmp.wUoJIvfzzI + return 0 + yq eval ' (.spec.template.spec.containers[].image = "perconalab/percona-server-mongodb-operator:PR-2152-4461031b") | ((.. | select(.[] == "DISABLE_TELEMETRY")) |= .value="true") | ((.. | select(.[] == "LOG_LEVEL")) |= .value="DEBUG")' /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/deploy/cw-operator.yaml + kubectl_bin apply -n psmdb-operator -f - ++ mktemp + local LAST_OUT=/tmp/tmp.k6Eb0nfqaf ++ mktemp + local LAST_ERR=/tmp/tmp.E84ZNGtTUp + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl apply -n psmdb-operator -f - + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.k6Eb0nfqaf deployment.apps/percona-server-mongodb-operator created + cat /tmp/tmp.E84ZNGtTUp + rm /tmp/tmp.k6Eb0nfqaf /tmp/tmp.E84ZNGtTUp + return 0 + sleep 20 ++ get_operator_pod ++ kubectl_bin get pods --selector=name=percona-server-mongodb-operator -o 'jsonpath={.items[].metadata.name}' -n psmdb-operator +++ mktemp ++ local LAST_OUT=/tmp/tmp.qiDBaqlp0W +++ mktemp ++ local LAST_ERR=/tmp/tmp.fDjbQjkKRR ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get pods --selector=name=percona-server-mongodb-operator -o 'jsonpath={.items[].metadata.name}' -n psmdb-operator ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.qiDBaqlp0W ++ cat /tmp/tmp.fDjbQjkKRR ++ rm /tmp/tmp.qiDBaqlp0W /tmp/tmp.fDjbQjkKRR ++ return 0 + wait_operator_pod percona-server-mongodb-operator-78c57f9588-4pmzt + local pod=percona-server-mongodb-operator-78c57f9588-4pmzt + set +o xtrace waiting for pod/percona-server-mongodb-operator-78c57f9588-4pmzt to be ready.OK + echo 'Print operator info from log' Print operator info from log + grep 'Manager starting up' ++ get_operator_pod ++ kubectl_bin get pods --selector=name=percona-server-mongodb-operator -o 'jsonpath={.items[].metadata.name}' -n psmdb-operator +++ mktemp ++ local LAST_OUT=/tmp/tmp.i0CoWHSyYP +++ mktemp ++ local LAST_ERR=/tmp/tmp.X3vI2GH5ZZ ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get pods --selector=name=percona-server-mongodb-operator -o 'jsonpath={.items[].metadata.name}' -n psmdb-operator ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.i0CoWHSyYP ++ cat /tmp/tmp.X3vI2GH5ZZ ++ rm /tmp/tmp.i0CoWHSyYP /tmp/tmp.X3vI2GH5ZZ ++ return 0 + kubectl_bin logs -n psmdb-operator percona-server-mongodb-operator-78c57f9588-4pmzt ++ mktemp + local LAST_OUT=/tmp/tmp.4a1MW5toan ++ mktemp + local LAST_ERR=/tmp/tmp.Td68KcXJu4 + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl logs -n psmdb-operator percona-server-mongodb-operator-78c57f9588-4pmzt + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.4a1MW5toan + cat /tmp/tmp.Td68KcXJu4 + rm /tmp/tmp.4a1MW5toan /tmp/tmp.Td68KcXJu4 + return 0 2025-12-18T19:52:19.574Z INFO setup Manager starting up {"gitCommit": "4461031b25c11e5b29d77d465c058b936127aac2", "gitBranch": "PR-2152-4461031b", "buildTime": "", "goVersion": "go1.25.5", "os": "linux", "arch": "amd64"} + create_namespace security-context-11319 + local namespace=security-context-11319 + local skip_clean_namespace= + [[ 1 == 1 ]] + [[ -z '' ]] + destroy_chaos_mesh ++ helm list --all-namespaces --filter chaos-mesh ++ tail -n1 ++ awk '-F ' '{print $2}' ++ sed s/NAMESPACE// + local chaos_mesh_ns= + desc 'destroy chaos-mesh' + set +o xtrace ----------------------------------------------------------------------------------- destroy chaos-mesh ----------------------------------------------------------------------------------- + '[' -n '' ']' ++ kubectl get MutatingWebhookConfiguration ++ grep chaos-mesh ++ awk '{print $1}' + timeout 30 kubectl delete MutatingWebhookConfiguration error: resource(s) were provided, but no name was specified + : ++ kubectl get ValidatingWebhookConfiguration ++ grep chaos-mesh ++ awk '{print $1}' + timeout 30 kubectl delete ValidatingWebhookConfiguration error: resource(s) were provided, but no name was specified + : ++ kubectl get ValidatingWebhookConfiguration ++ grep validate-auth ++ awk '{print $1}' + timeout 30 kubectl delete ValidatingWebhookConfiguration error: resource(s) were provided, but no name was specified + : ++ kubectl api-resources ++ grep chaos-mesh ++ awk '{print $1}' ++ kubectl get crd ++ grep chaos-mesh.org ++ awk '{print $1}' + timeout 30 kubectl delete crd error: resource(s) were provided, but no name was specified + : ++ kubectl get clusterrolebinding ++ grep chaos-mesh ++ awk '{print $1}' + timeout 30 kubectl delete clusterrolebinding error: resource(s) were provided, but no name was specified + : ++ kubectl get clusterrole ++ grep chaos-mesh ++ awk '{print $1}' + timeout 30 kubectl delete clusterrole error: resource(s) were provided, but no name was specified + : + desc 'cleaned up all old namespaces' + set +o xtrace ----------------------------------------------------------------------------------- cleaned up all old namespaces ----------------------------------------------------------------------------------- + kubectl_bin get ns + egrep -v '^kube-|^default|Terminating|psmdb-operator|openshift|^gke-|^gmp-|^NAME' + awk '{print$1}' + '[' -n '' ']' + xargs kubectl delete ns + desc 'cleaned up old namespaces security-context-11319' + set +o xtrace ----------------------------------------------------------------------------------- cleaned up old namespaces security-context-11319 ----------------------------------------------------------------------------------- + kubectl_bin delete namespace security-context-11319 --ignore-not-found ++ mktemp ++ mktemp + local LAST_OUT=/tmp/tmp.Ztkflzv0V5 ++ mktemp egrep: warning: egrep is obsolescent; using grep -E + local LAST_ERR=/tmp/tmp.sQHGmkixcX + local exit_status=0 + local LAST_OUT=/tmp/tmp.wMK6xErY9h + local timeout=4 ++ seq 0 2 ++ mktemp + for i in $(seq 0 2) + set +e + kubectl get ns + local LAST_ERR=/tmp/tmp.zVHp5zqzgs + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl delete namespace security-context-11319 --ignore-not-found + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.Ztkflzv0V5 + cat /tmp/tmp.sQHGmkixcX + rm /tmp/tmp.Ztkflzv0V5 /tmp/tmp.sQHGmkixcX + return 0 error: resource(s) were provided, but no name was specified + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.wMK6xErY9h + cat /tmp/tmp.zVHp5zqzgs + rm /tmp/tmp.wMK6xErY9h /tmp/tmp.zVHp5zqzgs + return 0 + kubectl_bin wait --for=delete namespace security-context-11319 ++ mktemp + local LAST_OUT=/tmp/tmp.AHtAoOiKUR ++ mktemp + local LAST_ERR=/tmp/tmp.nFKFmiGfua + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl wait --for=delete namespace security-context-11319 + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.AHtAoOiKUR + cat /tmp/tmp.nFKFmiGfua + rm /tmp/tmp.AHtAoOiKUR /tmp/tmp.nFKFmiGfua + return 0 + desc 'create namespace security-context-11319' + set +o xtrace ----------------------------------------------------------------------------------- create namespace security-context-11319 ----------------------------------------------------------------------------------- + kubectl_bin create namespace security-context-11319 ++ mktemp + local LAST_OUT=/tmp/tmp.tIZQ9cfI57 ++ mktemp + local LAST_ERR=/tmp/tmp.4HrpA5po1L + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl create namespace security-context-11319 + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.tIZQ9cfI57 namespace/security-context-11319 created + cat /tmp/tmp.4HrpA5po1L + rm /tmp/tmp.tIZQ9cfI57 /tmp/tmp.4HrpA5po1L + return 0 + set_kube_ctx security-context-11319 + local namespace=security-context-11319 ++ kubectl_bin config current-context +++ mktemp ++ local LAST_OUT=/tmp/tmp.A4ZjmYXSn2 +++ mktemp ++ local LAST_ERR=/tmp/tmp.np82V3t7ih ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl config current-context ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.A4ZjmYXSn2 ++ cat /tmp/tmp.np82V3t7ih ++ rm /tmp/tmp.A4ZjmYXSn2 /tmp/tmp.np82V3t7ih ++ return 0 + kubectl_bin config set-context gke_cloud-dev-112233_us-central1-a_jen-psmdb-2152-4461031b-2-cluster10 --namespace=security-context-11319 ++ mktemp + local LAST_OUT=/tmp/tmp.oYhw0gSw3O ++ mktemp + local LAST_ERR=/tmp/tmp.l7yS5HVbLi + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl config set-context gke_cloud-dev-112233_us-central1-a_jen-psmdb-2152-4461031b-2-cluster10 --namespace=security-context-11319 + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.oYhw0gSw3O Context "gke_cloud-dev-112233_us-central1-a_jen-psmdb-2152-4461031b-2-cluster10" modified. + cat /tmp/tmp.l7yS5HVbLi + rm /tmp/tmp.oYhw0gSw3O /tmp/tmp.l7yS5HVbLi + return 0 + desc 'create secrets and start client' + set +o xtrace ----------------------------------------------------------------------------------- create secrets and start client ----------------------------------------------------------------------------------- + kubectl_bin apply -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/conf/secrets.yml -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/conf/client.yml -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/conf/minio-secret.yml ++ mktemp + local LAST_OUT=/tmp/tmp.S1Pv1fqqzx ++ mktemp + local LAST_ERR=/tmp/tmp.F3IqsbohxS + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl apply -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/conf/secrets.yml -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/conf/client.yml -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/conf/minio-secret.yml + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.S1Pv1fqqzx secret/some-users created deployment.apps/psmdb-client created secret/minio-secret created + cat /tmp/tmp.F3IqsbohxS + rm /tmp/tmp.S1Pv1fqqzx /tmp/tmp.F3IqsbohxS + return 0 + desc 'create additional service account' + set +o xtrace ----------------------------------------------------------------------------------- create additional service account ----------------------------------------------------------------------------------- + kubectl_bin apply -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/conf/service-account.yml ++ mktemp + local LAST_OUT=/tmp/tmp.VdtRhcVbLM ++ mktemp + local LAST_ERR=/tmp/tmp.ezjniKHfbO + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl apply -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/conf/service-account.yml + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.VdtRhcVbLM serviceaccount/percona-server-mongodb-operator-workload created + cat /tmp/tmp.ezjniKHfbO + rm /tmp/tmp.VdtRhcVbLM /tmp/tmp.ezjniKHfbO + return 0 + [[ -n '' ]] + cluster=sec-context + desc 'create first PSMDB cluster sec-context' + set +o xtrace ----------------------------------------------------------------------------------- create first PSMDB cluster sec-context ----------------------------------------------------------------------------------- + spinup_psmdb sec-context-rs0 /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/conf/sec-context-rs0.yml + local cluster=sec-context-rs0 + local config=/mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/conf/sec-context-rs0.yml + local size=3 + desc 'create first PSMDB cluster' + set +o xtrace ----------------------------------------------------------------------------------- create first PSMDB cluster ----------------------------------------------------------------------------------- + apply_cluster /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/conf/sec-context-rs0.yml + '[' -z '' ']' + cat_config /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/conf/sec-context-rs0.yml + kubectl_bin apply -f - ++ mktemp + yq eval '(.spec | select(has("pmm"))).pmm.image = "percona/pmm-client:2.44.1-1"' + yq eval '(.spec | select(has("initImage"))).initImage = "perconalab/percona-server-mongodb-operator:PR-2152-4461031b"' + cat /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/conf/sec-context-rs0.yml + local LAST_OUT=/tmp/tmp.TD9ZCuBNzo ++ mktemp + yq eval '(.spec | select(.image == null)).image = "perconalab/percona-server-mongodb-operator:main-mongod8.0"' + yq eval '.spec.upgradeOptions.apply="Never"' + yq eval '(.spec | select(has("backup"))).backup.image = "perconalab/percona-server-mongodb-operator:main-backup"' + local LAST_ERR=/tmp/tmp.KQd5gOnLnS + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl apply -f - + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.TD9ZCuBNzo perconaservermongodb.psmdb.percona.com/sec-context created + cat /tmp/tmp.KQd5gOnLnS + rm /tmp/tmp.TD9ZCuBNzo /tmp/tmp.KQd5gOnLnS + return 0 + desc 'check if Pod is started' + set +o xtrace ----------------------------------------------------------------------------------- check if Pod is started ----------------------------------------------------------------------------------- + wait_for_running sec-context-rs0 3 + local name=sec-context-rs0 + let last_pod=2 + local check_cluster_readyness=true + set_debug + [[ 1 == 1 ]] + set -o xtrace + local rs_name=rs0 + local cluster_name=sec-context ++ seq 0 2 + for i in $(seq 0 $last_pod) + [[ 0 -eq 2 ]] + wait_pod sec-context-rs0-0 + local pod=sec-context-rs0-0 + set +o xtrace waiting for pod/sec-context-rs0-0 to be ready..........OK + for i in $(seq 0 $last_pod) + [[ 1 -eq 2 ]] + wait_pod sec-context-rs0-1 + local pod=sec-context-rs0-1 + set +o xtrace waiting for pod/sec-context-rs0-1 to be ready...........OK + for i in $(seq 0 $last_pod) + [[ 2 -eq 2 ]] ++ kubectl_bin get psmdb sec-context -o 'jsonpath={.spec.replsets[?(@.name=="rs0")].arbiter.enabled}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.UGRZtWTQUE +++ mktemp ++ local LAST_ERR=/tmp/tmp.J1IM0wljUG ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get psmdb sec-context -o 'jsonpath={.spec.replsets[?(@.name=="rs0")].arbiter.enabled}' ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.UGRZtWTQUE ++ cat /tmp/tmp.J1IM0wljUG ++ rm /tmp/tmp.UGRZtWTQUE /tmp/tmp.J1IM0wljUG ++ return 0 + [[ '' == \t\r\u\e ]] + wait_pod sec-context-rs0-2 + local pod=sec-context-rs0-2 + set +o xtrace waiting for pod/sec-context-rs0-2 to be ready.............OK ++ kubectl_bin get psmdb sec-context -o 'jsonpath={.spec.replsets[?(@.name=="rs0")].nonvoting.enabled}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.qdUZhV6nH0 +++ mktemp ++ local LAST_ERR=/tmp/tmp.ydwW3UFwuH ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get psmdb sec-context -o 'jsonpath={.spec.replsets[?(@.name=="rs0")].nonvoting.enabled}' ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.qdUZhV6nH0 ++ cat /tmp/tmp.ydwW3UFwuH ++ rm /tmp/tmp.qdUZhV6nH0 /tmp/tmp.ydwW3UFwuH ++ return 0 + [[ '' == \t\r\u\e ]] ++ kubectl_bin get psmdb sec-context -o 'jsonpath={.spec.replsets[?(@.name=="rs0")].hidden.enabled}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.0FtMRyEriE +++ mktemp ++ local LAST_ERR=/tmp/tmp.kJDcjuPkz1 ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get psmdb sec-context -o 'jsonpath={.spec.replsets[?(@.name=="rs0")].hidden.enabled}' ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.0FtMRyEriE ++ cat /tmp/tmp.kJDcjuPkz1 ++ rm /tmp/tmp.0FtMRyEriE /tmp/tmp.kJDcjuPkz1 ++ return 0 + [[ '' == \t\r\u\e ]] + sleep 10 + [[ true == \t\r\u\e ]] + set +x Waiting for cluster readyness + sleep 20 + compare_kubectl statefulset/sec-context-rs0 + local resource=statefulset/sec-context-rs0 + local postfix= + local skip_generation_check= + local expected_result=/mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/compare/statefulset_sec-context-rs0.yml + local new_result=/tmp/tmp.je0fzdEQcM/statefulset_sec-context-rs0.yml + '[' -n '' -a -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/compare/statefulset_sec-context-rs0-oc.yml ']' + kubectl_bin get -o yaml statefulset/sec-context-rs0 + yq eval ' del(.metadata.ownerReferences[].apiVersion) | del(.metadata.managedFields) | del(.. | select(has("creationTimestamp")).creationTimestamp) | del(.. | select(has("namespace")).namespace) | del(.. | select(has("uid")).uid) | del(.metadata.resourceVersion) | del(.spec.template.spec.containers[].env[] | select(.name == "NAMESPACE")) | del(.metadata.selfLink) | del(.metadata.annotations."cloud.google.com/neg") | del(.metadata.annotations."kubectl.kubernetes.io/last-applied-configuration") | del(.. | select(has("image")).image) | del(.. | select(has("clusterIP")).clusterIP) | del(.. | select(has("clusterIPs")).clusterIPs) | del(.. | select(has("dataSource")).dataSource) | del(.. | select(has("procMount")).procMount) | del(.. | select(has("storageClassName")).storageClassName) | del(.. | select(has("finalizers")).finalizers) | del(.. | select(has("kubernetes.io/pvc-protection"))."kubernetes.io/pvc-protection") | del(.. | select(has("volumeName")).volumeName) | del(.. | select(has("volume.beta.kubernetes.io/storage-provisioner"))."volume.beta.kubernetes.io/storage-provisioner") | del(.. | select(has("volume.kubernetes.io/storage-provisioner"))."volume.kubernetes.io/storage-provisioner") | del(.spec.volumeMode) | del(.. | select(has("volume.kubernetes.io/selected-node"))."volume.kubernetes.io/selected-node") | del(.. | select(has("percona.com/last-config-hash"))."percona.com/last-config-hash") | del(.. | select(has("percona.com/configuration-hash"))."percona.com/configuration-hash") | del(.. | select(has("percona.com/ssl-hash"))."percona.com/ssl-hash") | del(.. | select(has("percona.com/ssl-internal-hash"))."percona.com/ssl-internal-hash") | del(.spec.volumeClaimTemplates[].spec.volumeMode | select(. == "Filesystem")) | del(.. | select(has("healthCheckNodePort")).healthCheckNodePort) | del(.. | select(has("nodePort")).nodePort) | del(.status) | (.. | select(tag == "!!str")) |= sub("security-context-11319", "NAME_SPACE") | del(.spec.volumeClaimTemplates[].apiVersion) | del(.spec.volumeClaimTemplates[].kind) | del(.spec.ipFamilies) | del(.spec.ipFamilyPolicy) | (.. | select(. == "extensions/v1beta1")) = "apps/v1" | (.. | select(. == "batch/v1beta1")) = "batch/v1" ' - ++ mktemp + local LAST_OUT=/tmp/tmp.FWTMk9kfIT ++ mktemp + local LAST_ERR=/tmp/tmp.KcNAswBQ1J + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl get -o yaml statefulset/sec-context-rs0 + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.FWTMk9kfIT + cat /tmp/tmp.KcNAswBQ1J + rm /tmp/tmp.FWTMk9kfIT /tmp/tmp.KcNAswBQ1J + return 0 + yq -i eval 'del(.spec.persistentVolumeClaimRetentionPolicy)' /tmp/tmp.je0fzdEQcM/statefulset_sec-context-rs0.yml + version_gt 1.22 ++ echo '1.31 >= 1.22' ++ bc -l + '[' 1 -eq 1 ']' + return 0 + yq -i eval 'del(.spec.internalTrafficPolicy)' /tmp/tmp.je0fzdEQcM/statefulset_sec-context-rs0.yml + yq -i eval 'del(.spec.allocateLoadBalancerNodePorts)' /tmp/tmp.je0fzdEQcM/statefulset_sec-context-rs0.yml + [[ /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/compare/statefulset_sec-context-rs0.yml == */cronjob* ]] + '[' -n '' ']' + [[ 0 -eq 0 ]] + diff -u /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/compare/statefulset_sec-context-rs0.yml /tmp/tmp.je0fzdEQcM/statefulset_sec-context-rs0.yml + log 'compare_kubectl: statefulset/sec-context-rs0 OK' + set +o xtrace [2025-12-18T19:55:00+0000] compare_kubectl: statefulset/sec-context-rs0 OK + desc 'write data' + set +o xtrace ----------------------------------------------------------------------------------- write data ----------------------------------------------------------------------------------- + run_mongo 'db.createUser({user: "myApp", pwd: "myPass", roles: [{ db: "myApp", role: "readWrite" }]})' userAdmin:userAdmin123456@sec-context-rs0.security-context-11319 + local 'command=db.createUser({user: "myApp", pwd: "myPass", roles: [{ db: "myApp", role: "readWrite" }]})' + local uri=userAdmin:userAdmin123456@sec-context-rs0.security-context-11319 + local driver=mongodb+srv + local suffix=.svc.cluster.local + local mongo_flag= + local replica_set=rs0 + [[ userAdmin:userAdmin123456@sec-context-rs0.security-context-11319 == *cfg* ]] ++ kubectl_bin get pods --selector=name=psmdb-client -o 'jsonpath={.items[].metadata.name}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.sOx3RMTQ5m +++ mktemp ++ local LAST_ERR=/tmp/tmp.HKzN472Zqx ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get pods --selector=name=psmdb-client -o 'jsonpath={.items[].metadata.name}' ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.sOx3RMTQ5m ++ cat /tmp/tmp.HKzN472Zqx ++ rm /tmp/tmp.sOx3RMTQ5m /tmp/tmp.HKzN472Zqx ++ return 0 + local client_container=psmdb-client-696897d69b-2rrl4 + kubectl_bin exec psmdb-client-696897d69b-2rrl4 -- bash -c 'printf '\''db.createUser({user: "myApp", pwd: "myPass", roles: [{ db: "myApp", role: "readWrite" }]})\n'\'' | mongo mongodb+srv://userAdmin:userAdmin123456@sec-context-rs0.security-context-11319.svc.cluster.local/admin?ssl=false\&replicaSet=rs0 ' ++ mktemp + local LAST_OUT=/tmp/tmp.HlE1KbAGJg ++ mktemp + local LAST_ERR=/tmp/tmp.QKDjpo72A2 + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl exec psmdb-client-696897d69b-2rrl4 -- bash -c 'printf '\''db.createUser({user: "myApp", pwd: "myPass", roles: [{ db: "myApp", role: "readWrite" }]})\n'\'' | mongo mongodb+srv://userAdmin:userAdmin123456@sec-context-rs0.security-context-11319.svc.cluster.local/admin?ssl=false\&replicaSet=rs0 ' + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.HlE1KbAGJg Percona Server for MongoDB shell version v4.4.29-28 connecting to: mongodb://sec-context-rs0-1.sec-context-rs0.security-context-11319.svc.cluster.local:27017,sec-context-rs0-2.sec-context-rs0.security-context-11319.svc.cluster.local:27017,sec-context-rs0-0.sec-context-rs0.security-context-11319.svc.cluster.local:27017/admin?compressors=disabled&gssapiServiceName=mongodb&replicaSet=rs0&ssl=false Implicit session: session { "id" : UUID("16a66f98-5251-4394-9056-1f06fd4b482b") } Percona Server for MongoDB server version: v8.0.16-5 WARNING: shell and server versions do not match Successfully added user: { "user" : "myApp", "roles" : [ { "db" : "myApp", "role" : "readWrite" } ] } bye + cat /tmp/tmp.QKDjpo72A2 + rm /tmp/tmp.HlE1KbAGJg /tmp/tmp.QKDjpo72A2 + return 0 + run_mongo 'use myApp\n db.test.insert({ x: 100500 })' myApp:myPass@sec-context-rs0.security-context-11319 + local 'command=use myApp\n db.test.insert({ x: 100500 })' + local uri=myApp:myPass@sec-context-rs0.security-context-11319 + local driver=mongodb+srv + local suffix=.svc.cluster.local + local mongo_flag= + local replica_set=rs0 + [[ myApp:myPass@sec-context-rs0.security-context-11319 == *cfg* ]] ++ kubectl_bin get pods --selector=name=psmdb-client -o 'jsonpath={.items[].metadata.name}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.VqCNelTgJ2 +++ mktemp ++ local LAST_ERR=/tmp/tmp.3zz2NVXxIX ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get pods --selector=name=psmdb-client -o 'jsonpath={.items[].metadata.name}' ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.VqCNelTgJ2 ++ cat /tmp/tmp.3zz2NVXxIX ++ rm /tmp/tmp.VqCNelTgJ2 /tmp/tmp.3zz2NVXxIX ++ return 0 + local client_container=psmdb-client-696897d69b-2rrl4 + kubectl_bin exec psmdb-client-696897d69b-2rrl4 -- bash -c 'printf '\''use myApp\n db.test.insert({ x: 100500 })\n'\'' | mongo mongodb+srv://myApp:myPass@sec-context-rs0.security-context-11319.svc.cluster.local/admin?ssl=false\&replicaSet=rs0 ' ++ mktemp + local LAST_OUT=/tmp/tmp.w00sFM1cZd ++ mktemp + local LAST_ERR=/tmp/tmp.R6aWtKFqUE + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl exec psmdb-client-696897d69b-2rrl4 -- bash -c 'printf '\''use myApp\n db.test.insert({ x: 100500 })\n'\'' | mongo mongodb+srv://myApp:myPass@sec-context-rs0.security-context-11319.svc.cluster.local/admin?ssl=false\&replicaSet=rs0 ' + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.w00sFM1cZd Percona Server for MongoDB shell version v4.4.29-28 connecting to: mongodb://sec-context-rs0-0.sec-context-rs0.security-context-11319.svc.cluster.local:27017,sec-context-rs0-1.sec-context-rs0.security-context-11319.svc.cluster.local:27017,sec-context-rs0-2.sec-context-rs0.security-context-11319.svc.cluster.local:27017/admin?compressors=disabled&gssapiServiceName=mongodb&replicaSet=rs0&ssl=false Implicit session: session { "id" : UUID("b41d1553-2f04-499b-b3c4-159f63cc2ce1") } Percona Server for MongoDB server version: v8.0.16-5 WARNING: shell and server versions do not match switched to db myApp WriteResult({ "nInserted" : 1 }) bye + cat /tmp/tmp.R6aWtKFqUE + rm /tmp/tmp.w00sFM1cZd /tmp/tmp.R6aWtKFqUE + return 0 + desc 'check if statefulset created with expected config' + set +o xtrace ----------------------------------------------------------------------------------- check if statefulset created with expected config ----------------------------------------------------------------------------------- + compare_kubectl statefulset/sec-context-rs0 + local resource=statefulset/sec-context-rs0 + local postfix= + local skip_generation_check= + local expected_result=/mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/compare/statefulset_sec-context-rs0.yml + local new_result=/tmp/tmp.je0fzdEQcM/statefulset_sec-context-rs0.yml + '[' -n '' -a -f /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/compare/statefulset_sec-context-rs0-oc.yml ']' + kubectl_bin get -o yaml statefulset/sec-context-rs0 + yq eval ' del(.metadata.ownerReferences[].apiVersion) | del(.metadata.managedFields) | del(.. | select(has("creationTimestamp")).creationTimestamp) | del(.. | select(has("namespace")).namespace) | del(.. | select(has("uid")).uid) | del(.metadata.resourceVersion) | del(.spec.template.spec.containers[].env[] | select(.name == "NAMESPACE")) | del(.metadata.selfLink) | del(.metadata.annotations."cloud.google.com/neg") | del(.metadata.annotations."kubectl.kubernetes.io/last-applied-configuration") | del(.. | select(has("image")).image) | del(.. | select(has("clusterIP")).clusterIP) | del(.. | select(has("clusterIPs")).clusterIPs) | del(.. | select(has("dataSource")).dataSource) | del(.. | select(has("procMount")).procMount) | del(.. | select(has("storageClassName")).storageClassName) | del(.. | select(has("finalizers")).finalizers) | del(.. | select(has("kubernetes.io/pvc-protection"))."kubernetes.io/pvc-protection") | del(.. | select(has("volumeName")).volumeName) | del(.. | select(has("volume.beta.kubernetes.io/storage-provisioner"))."volume.beta.kubernetes.io/storage-provisioner") | del(.. | select(has("volume.kubernetes.io/storage-provisioner"))."volume.kubernetes.io/storage-provisioner") | del(.spec.volumeMode) | del(.. | select(has("volume.kubernetes.io/selected-node"))."volume.kubernetes.io/selected-node") | del(.. | select(has("percona.com/last-config-hash"))."percona.com/last-config-hash") | del(.. | select(has("percona.com/configuration-hash"))."percona.com/configuration-hash") | del(.. | select(has("percona.com/ssl-hash"))."percona.com/ssl-hash") | del(.. | select(has("percona.com/ssl-internal-hash"))."percona.com/ssl-internal-hash") | del(.spec.volumeClaimTemplates[].spec.volumeMode | select(. == "Filesystem")) | del(.. | select(has("healthCheckNodePort")).healthCheckNodePort) | del(.. | select(has("nodePort")).nodePort) | del(.status) | (.. | select(tag == "!!str")) |= sub("security-context-11319", "NAME_SPACE") | del(.spec.volumeClaimTemplates[].apiVersion) | del(.spec.volumeClaimTemplates[].kind) | del(.spec.ipFamilies) | del(.spec.ipFamilyPolicy) | (.. | select(. == "extensions/v1beta1")) = "apps/v1" | (.. | select(. == "batch/v1beta1")) = "batch/v1" ' - ++ mktemp + local LAST_OUT=/tmp/tmp.OOiXGyXAnO ++ mktemp + local LAST_ERR=/tmp/tmp.cUKb28eyak + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl get -o yaml statefulset/sec-context-rs0 + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.OOiXGyXAnO + cat /tmp/tmp.cUKb28eyak + rm /tmp/tmp.OOiXGyXAnO /tmp/tmp.cUKb28eyak + return 0 + yq -i eval 'del(.spec.persistentVolumeClaimRetentionPolicy)' /tmp/tmp.je0fzdEQcM/statefulset_sec-context-rs0.yml + version_gt 1.22 ++ echo '1.31 >= 1.22' ++ bc -l + '[' 1 -eq 1 ']' + return 0 + yq -i eval 'del(.spec.internalTrafficPolicy)' /tmp/tmp.je0fzdEQcM/statefulset_sec-context-rs0.yml + yq -i eval 'del(.spec.allocateLoadBalancerNodePorts)' /tmp/tmp.je0fzdEQcM/statefulset_sec-context-rs0.yml + [[ /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/compare/statefulset_sec-context-rs0.yml == */cronjob* ]] + '[' -n '' ']' + [[ 0 -eq 0 ]] + diff -u /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/compare/statefulset_sec-context-rs0.yml /tmp/tmp.je0fzdEQcM/statefulset_sec-context-rs0.yml + log 'compare_kubectl: statefulset/sec-context-rs0 OK' + set +o xtrace [2025-12-18T19:55:06+0000] compare_kubectl: statefulset/sec-context-rs0 OK + deploy_minio + desc 'install Minio' + set +o xtrace ----------------------------------------------------------------------------------- install Minio ----------------------------------------------------------------------------------- + helm uninstall minio-service Error: uninstall: Release not loaded: minio-service: release: not found + : + helm repo remove minio "minio" has been removed from your repositories + helm repo add minio https://charts.min.io/ "minio" has been added to your repositories + retry 10 60 helm install minio-service --version 5.4.0 --set replicas=1 --set mode=standalone --set resources.requests.memory=256Mi --set rootUser=rootuser --set rootPassword=rootpass123 --set 'users[0].accessKey=some-access-key' --set 'users[0].secretKey=some-secret-key' --set 'users[0].policy=consoleAdmin' --set service.type=ClusterIP --set configPathmc=/tmp/.minio/ --set persistence.size=2G --set securityContext.enabled=false minio/minio + local max=10 + local delay=60 + shift 2 + local n=1 + helm install minio-service --version 5.4.0 --set replicas=1 --set mode=standalone --set resources.requests.memory=256Mi --set rootUser=rootuser --set rootPassword=rootpass123 --set 'users[0].accessKey=some-access-key' --set 'users[0].secretKey=some-secret-key' --set 'users[0].policy=consoleAdmin' --set service.type=ClusterIP --set configPathmc=/tmp/.minio/ --set persistence.size=2G --set securityContext.enabled=false minio/minio NAME: minio-service LAST DEPLOYED: Thu Dec 18 19:55:09 2025 NAMESPACE: security-context-11319 STATUS: deployed REVISION: 1 TEST SUITE: None NOTES: MinIO can be accessed via port 9000 on the following DNS name from within your cluster: minio-service.security-context-11319.cluster.local To access MinIO from localhost, run the below commands: 1. export POD_NAME=$(kubectl get pods --namespace security-context-11319 -l "release=minio-service" -o jsonpath="{.items[0].metadata.name}") 2. kubectl port-forward $POD_NAME 9000 --namespace security-context-11319 Read more about port forwarding here: http://kubernetes.io/docs/user-guide/kubectl/kubectl_port-forward/ You can now access MinIO server on http://localhost:9000. Follow the below steps to connect to MinIO server with mc client: 1. Download the MinIO mc client - https://min.io/docs/minio/linux/reference/minio-mc.html#quickstart 2. export MC_HOST_minio-service-local=http://$(kubectl get secret --namespace security-context-11319 minio-service -o jsonpath="{.data.rootUser}" | base64 --decode):$(kubectl get secret --namespace security-context-11319 minio-service -o jsonpath="{.data.rootPassword}" | base64 --decode)@localhost:9000 3. mc ls minio-service-local ++ kubectl_bin get pods --selector=release=minio-service -o 'jsonpath={.items[].metadata.name}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.zS9hI49UYq +++ mktemp ++ local LAST_ERR=/tmp/tmp.pOICkuCe69 ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get pods --selector=release=minio-service -o 'jsonpath={.items[].metadata.name}' ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.zS9hI49UYq ++ cat /tmp/tmp.pOICkuCe69 ++ rm /tmp/tmp.zS9hI49UYq /tmp/tmp.pOICkuCe69 ++ return 0 + MINIO_POD=minio-service-d9589b474-n8khw + wait_pod minio-service-d9589b474-n8khw + local pod=minio-service-d9589b474-n8khw + set +o xtrace waiting for pod/minio-service-d9589b474-n8khw to be ready.OK + '[' -n psmdb-operator ']' + kubectl_bin create svc -n psmdb-operator externalname minio-service --external-name=minio-service.security-context-11319.svc.cluster.local --tcp=9000 ++ mktemp + local LAST_OUT=/tmp/tmp.WJRGKoe5Mb ++ mktemp + local LAST_ERR=/tmp/tmp.8XBSiXbZA7 + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl create svc -n psmdb-operator externalname minio-service --external-name=minio-service.security-context-11319.svc.cluster.local --tcp=9000 + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.WJRGKoe5Mb service/minio-service created + cat /tmp/tmp.8XBSiXbZA7 + rm /tmp/tmp.WJRGKoe5Mb /tmp/tmp.8XBSiXbZA7 + return 0 + create_minio_bucket operator-testing + local bucket=operator-testing + kubectl_bin run -i --rm aws-cli --image=perconalab/awscli --restart=Never -- bash -c 'AWS_ACCESS_KEY_ID=some-access-key AWS_SECRET_ACCESS_KEY=some-secret-key AWS_DEFAULT_REGION=us-east-1 /usr/bin/aws --endpoint-url http://minio-service:9000 s3 mb s3://operator-testing' ++ mktemp + local LAST_OUT=/tmp/tmp.0iBunE7fXN ++ mktemp + local LAST_ERR=/tmp/tmp.oklyLch6ig + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl run -i --rm aws-cli --image=perconalab/awscli --restart=Never -- bash -c 'AWS_ACCESS_KEY_ID=some-access-key AWS_SECRET_ACCESS_KEY=some-secret-key AWS_DEFAULT_REGION=us-east-1 /usr/bin/aws --endpoint-url http://minio-service:9000 s3 mb s3://operator-testing' + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.0iBunE7fXN make_bucket: operator-testing pod "aws-cli" deleted from security-context-11319 namespace + cat /tmp/tmp.oklyLch6ig All commands and output from this session will be recorded in container logs, including credentials and sensitive information passed through the command prompt. If you don't see a command prompt, try pressing enter. warning: couldn't attach to pod/aws-cli, falling back to streaming logs: Internal error occurred: unable to upgrade connection: container aws-cli not found in pod aws-cli_security-context-11319 + rm /tmp/tmp.0iBunE7fXN /tmp/tmp.oklyLch6ig + return 0 + desc 'change security context' + set +o xtrace ----------------------------------------------------------------------------------- change security context ----------------------------------------------------------------------------------- + postfix=-changed + apply_cluster /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/conf/sec-context-rs0-changed.yml + '[' -z '' ']' + cat_config /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/conf/sec-context-rs0-changed.yml + kubectl_bin apply -f - + cat /mnt/jenkins/workspace/cloud-psmdb-operator_PR-2152/e2e-tests/security-context/conf/sec-context-rs0-changed.yml + yq eval '(.spec | select(.image == null)).image = "perconalab/percona-server-mongodb-operator:main-mongod8.0"' + yq eval '(.spec | select(has("pmm"))).pmm.image = "percona/pmm-client:2.44.1-1"' ++ mktemp + yq eval '(.spec | select(has("initImage"))).initImage = "perconalab/percona-server-mongodb-operator:PR-2152-4461031b"' + yq eval '(.spec | select(has("backup"))).backup.image = "perconalab/percona-server-mongodb-operator:main-backup"' + yq eval '.spec.upgradeOptions.apply="Never"' + local LAST_OUT=/tmp/tmp.TKamV4kRBa ++ mktemp + local LAST_ERR=/tmp/tmp.UfKIsJYat4 + local exit_status=0 + local timeout=4 ++ seq 0 2 + for i in $(seq 0 2) + set +e + kubectl apply -f - + exit_status=0 + set -e + '[' 0 '!=' 0 -a -n 1 ']' + break + cat /tmp/tmp.TKamV4kRBa perconaservermongodb.psmdb.percona.com/sec-context configured + cat /tmp/tmp.UfKIsJYat4 + rm /tmp/tmp.TKamV4kRBa /tmp/tmp.UfKIsJYat4 + return 0 + sleep 20 + wait_for_running sec-context-rs0 3 + local name=sec-context-rs0 + let last_pod=2 + local check_cluster_readyness=true + set_debug + [[ 1 == 1 ]] + set -o xtrace + local rs_name=rs0 + local cluster_name=sec-context ++ seq 0 2 + for i in $(seq 0 $last_pod) + [[ 0 -eq 2 ]] + wait_pod sec-context-rs0-0 + local pod=sec-context-rs0-0 + set +o xtrace waiting for pod/sec-context-rs0-0 to be ready.OK + for i in $(seq 0 $last_pod) + [[ 1 -eq 2 ]] + wait_pod sec-context-rs0-1 + local pod=sec-context-rs0-1 + set +o xtrace waiting for pod/sec-context-rs0-1 to be ready.OK + for i in $(seq 0 $last_pod) + [[ 2 -eq 2 ]] ++ kubectl_bin get psmdb sec-context -o 'jsonpath={.spec.replsets[?(@.name=="rs0")].arbiter.enabled}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.FNEPlcIsgo +++ mktemp ++ local LAST_ERR=/tmp/tmp.o6ce7GfHuW ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get psmdb sec-context -o 'jsonpath={.spec.replsets[?(@.name=="rs0")].arbiter.enabled}' ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.FNEPlcIsgo ++ cat /tmp/tmp.o6ce7GfHuW ++ rm /tmp/tmp.FNEPlcIsgo /tmp/tmp.o6ce7GfHuW ++ return 0 + [[ '' == \t\r\u\e ]] + wait_pod sec-context-rs0-2 + local pod=sec-context-rs0-2 + set +o xtrace waiting for pod/sec-context-rs0-2 to be ready.....OK ++ kubectl_bin get psmdb sec-context -o 'jsonpath={.spec.replsets[?(@.name=="rs0")].nonvoting.enabled}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.P2BNovCWcG +++ mktemp ++ local LAST_ERR=/tmp/tmp.RsImTptlEE ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get psmdb sec-context -o 'jsonpath={.spec.replsets[?(@.name=="rs0")].nonvoting.enabled}' ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.P2BNovCWcG ++ cat /tmp/tmp.RsImTptlEE ++ rm /tmp/tmp.P2BNovCWcG /tmp/tmp.RsImTptlEE ++ return 0 + [[ '' == \t\r\u\e ]] ++ kubectl_bin get psmdb sec-context -o 'jsonpath={.spec.replsets[?(@.name=="rs0")].hidden.enabled}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.W3gmyaedi6 +++ mktemp ++ local LAST_ERR=/tmp/tmp.ilLSC9vIE8 ++ local exit_status=0 ++ local timeout=4 +++ seq 0 2 ++ for i in $(seq 0 2) ++ set +e ++ kubectl get psmdb sec-context -o 'jsonpath={.spec.replsets[?(@.name=="rs0")].hidden.enabled}' ++ exit_status=0 ++ set -e ++ '[' 0 '!=' 0 -a -n 1 ']' ++ break ++ cat /tmp/tmp.W3gmyaedi6 ++ cat /tmp/tmp.ilLSC9vIE8 ++ rm /tmp/tmp.W3gmyaedi6 /tmp/tmp.ilLSC9vIE8 ++ return 0 + [[ '' == \t\r\u\e ]] + sleep 10 + [[ true == \t\r\u\e ]] + set +x Waiting for cluster readyness.....................................................................................................................................................................................................................................................................................................................................................................................................................................................