++ echo 'Log: /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/logs/tls-issue-cert-manager.log' Log: /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/logs/tls-issue-cert-manager.log ++ '[' -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/conf/cloud-secret.yml ']' ++ SKIP_BACKUPS_TO_AWS_GCP= ++ oc get projects error: No Auth Provider found for name "gcp" +++ kubectl version -o json +++ jq -r .serverVersion.gitVersion +++ grep '\-eks\-' ++ '[' ']' ++ EKS=0 +++ kubectl version -o json +++ jq -r '.serverVersion.major + "." + .serverVersion.minor' +++ /usr/bin/sed -r 's/[^0-9.]+//g' ++ KUBE_VERSION=1.20 +++ helm version -c +++ /usr/bin/sed -re 's/.*SemVer:"([^"]+)".*/\1/; s/.*\bVersion:"([^"]+)".*/\1/' ++ HELM_VERSION=v3.8.1 ++ '[' v3 == v2 ']' + main + create_infra tls-issue-cert-manager-11948 + local ns=tls-issue-cert-manager-11948 + '[' -n pxc-operator ']' + kubectl get pxc --all-namespaces -o wide + xargs -L 1 sh -xc 'kubectl patch pxc -n $0 $1 --type=merge -p "{\"metadata\":{\"finalizers\":[]}}"' + grep -v NAMESPACE No resources found + kubectl patch pxc -n sh --type=merge -p '{"metadata":{"finalizers":[]}}' error: resource(s) were provided, but no name, label selector, or --all flag specified + : + kubectl_bin delete pxc --all --all-namespaces ++ mktemp + local LAST_OUT=/tmp/tmp.v5yNksUQFH ++ mktemp + local LAST_ERR=/tmp/tmp.Ruws4eWooA + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl delete pxc --all --all-namespaces + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.v5yNksUQFH No resources found + cat /tmp/tmp.Ruws4eWooA + rm /tmp/tmp.v5yNksUQFH /tmp/tmp.Ruws4eWooA + return 0 + kubectl_bin delete pxc-backup --all --all-namespaces ++ mktemp + local LAST_OUT=/tmp/tmp.lVTa0NjpYj ++ mktemp + local LAST_ERR=/tmp/tmp.NMQNYVfH7G + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl delete pxc-backup --all --all-namespaces + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.lVTa0NjpYj No resources found + cat /tmp/tmp.NMQNYVfH7G + rm /tmp/tmp.lVTa0NjpYj /tmp/tmp.NMQNYVfH7G + return 0 + kubectl_bin delete pxc-restore --all --all-namespaces ++ mktemp + local LAST_OUT=/tmp/tmp.kJ6rFuRDdF ++ mktemp + local LAST_ERR=/tmp/tmp.SyZ9gfie7e + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl delete pxc-restore --all --all-namespaces + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.kJ6rFuRDdF No resources found + cat /tmp/tmp.SyZ9gfie7e + rm /tmp/tmp.kJ6rFuRDdF /tmp/tmp.SyZ9gfie7e + return 0 + create_namespace pxc-operator + local namespace=pxc-operator + local skip_clean_namespace= + [[ 1 == 1 ]] + [[ -z '' ]] + kubectl_bin get ns + '[' '!' -z '' ']' + kubectl_bin delete namespace pxc-operator + xargs kubectl delete ns + awk '{print$1}' + egrep -v '^kube-|^default|Terminating|pxc-operator|openshift|^NAME' ++ mktemp + local LAST_OUT=/tmp/tmp.uKEtKGJ9Yj ++ mktemp + local LAST_ERR=/tmp/tmp.g4TUBW3Gle + local exit_status=0 ++ seq 0 2 ++ mktemp + for i in '$(seq 0 2)' + kubectl get ns + local LAST_OUT=/tmp/tmp.83xFDoj9HU ++ mktemp + local LAST_ERR=/tmp/tmp.Qso2cGDnKP + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl delete namespace pxc-operator + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.uKEtKGJ9Yj + cat /tmp/tmp.g4TUBW3Gle + rm /tmp/tmp.uKEtKGJ9Yj /tmp/tmp.g4TUBW3Gle + return 0 error: resource(s) were provided, but no name, label selector, or --all flag specified + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.83xFDoj9HU namespace "pxc-operator" deleted + cat /tmp/tmp.Qso2cGDnKP + rm /tmp/tmp.83xFDoj9HU /tmp/tmp.Qso2cGDnKP + return 0 + wait_for_delete namespace/pxc-operator + local res=namespace/pxc-operator + set +o xtrace namespace/pxc-operator - Error from server (NotFound): namespaces "pxc-operator" not found + kubectl_bin create namespace pxc-operator ++ mktemp + local LAST_OUT=/tmp/tmp.5PFL8KQikh ++ mktemp + local LAST_ERR=/tmp/tmp.YJQN6MZKCz + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl create namespace pxc-operator + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.5PFL8KQikh namespace/pxc-operator created + cat /tmp/tmp.YJQN6MZKCz + rm /tmp/tmp.5PFL8KQikh /tmp/tmp.YJQN6MZKCz + return 0 ++ kubectl_bin config current-context +++ mktemp ++ local LAST_OUT=/tmp/tmp.jU2h0QDxNu +++ mktemp ++ local LAST_ERR=/tmp/tmp.VgQw3K5cU6 ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl config current-context ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.jU2h0QDxNu ++ cat /tmp/tmp.VgQw3K5cU6 ++ rm /tmp/tmp.jU2h0QDxNu /tmp/tmp.VgQw3K5cU6 ++ return 0 + kubectl_bin config set-context gke_cloud-dev-112233_us-central1-a_jenkins-pxc-706f792a-basic --namespace=pxc-operator ++ mktemp + local LAST_OUT=/tmp/tmp.2ReWgYcAxA ++ mktemp + local LAST_ERR=/tmp/tmp.C4EW31ZYge + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl config set-context gke_cloud-dev-112233_us-central1-a_jenkins-pxc-706f792a-basic --namespace=pxc-operator + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.2ReWgYcAxA Context "gke_cloud-dev-112233_us-central1-a_jenkins-pxc-706f792a-basic" modified. + cat /tmp/tmp.C4EW31ZYge + rm /tmp/tmp.2ReWgYcAxA /tmp/tmp.C4EW31ZYge + return 0 + deploy_operator + desc 'start operator' + set +o xtrace ----------------------------------------------------------------------------------- start operator ----------------------------------------------------------------------------------- + kubectl_bin apply -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/deploy/crd.yaml ++ mktemp + local LAST_OUT=/tmp/tmp.9re1Nn7Q6Y ++ mktemp + local LAST_ERR=/tmp/tmp.OY9Ps30D5h + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl apply -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/deploy/crd.yaml + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.9re1Nn7Q6Y customresourcedefinition.apiextensions.k8s.io/perconaxtradbclusters.pxc.percona.com unchanged customresourcedefinition.apiextensions.k8s.io/perconaxtradbclusterbackups.pxc.percona.com unchanged customresourcedefinition.apiextensions.k8s.io/perconaxtradbclusterrestores.pxc.percona.com unchanged customresourcedefinition.apiextensions.k8s.io/perconaxtradbbackups.pxc.percona.com configured + cat /tmp/tmp.OY9Ps30D5h + rm /tmp/tmp.9re1Nn7Q6Y /tmp/tmp.OY9Ps30D5h + return 0 + '[' -n pxc-operator ']' + apply_rbac cw-rbac + local operator_namespace=pxc-operator + local rbac=cw-rbac + cat /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/deploy/cw-rbac.yaml + kubectl_bin apply -f - + sed -e 's^namespace: .*^namespace: pxc-operator^' ++ mktemp + local LAST_OUT=/tmp/tmp.NIvUlhFs78 ++ mktemp + local LAST_ERR=/tmp/tmp.uTUuzym64f + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl apply -f - + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.NIvUlhFs78 clusterrole.rbac.authorization.k8s.io/percona-xtradb-cluster-operator unchanged serviceaccount/percona-xtradb-cluster-operator created clusterrolebinding.rbac.authorization.k8s.io/service-account-percona-xtradb-cluster-operator unchanged + cat /tmp/tmp.uTUuzym64f + rm /tmp/tmp.NIvUlhFs78 /tmp/tmp.uTUuzym64f + return 0 + sed -e 's^image: .*^image: perconalab/percona-xtradb-cluster-operator:PR-1125-706f792a^' + cat /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/deploy/cw-operator.yaml + sed -e 's^failureThreshold: .*^failureThreshold: 10^' + kubectl_bin apply -f - ++ mktemp + local LAST_OUT=/tmp/tmp.mjWre5SpQy ++ mktemp + local LAST_ERR=/tmp/tmp.reGPjlPzoL + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl apply -f - + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.mjWre5SpQy deployment.apps/percona-xtradb-cluster-operator created service/percona-xtradb-cluster-operator created + cat /tmp/tmp.reGPjlPzoL + rm /tmp/tmp.mjWre5SpQy /tmp/tmp.reGPjlPzoL + return 0 + sleep 10 ++ get_operator_pod ++ local label_prefix=app.kubernetes.io/ +++ kubectl get pods --selector=app.kubernetes.io/name=percona-xtradb-cluster-operator -n pxc-operator +++ grep -c percona-xtradb-cluster-operator ++ local check_label=1 ++ [[ 1 -eq 0 ]] ++ kubectl_bin get pods --selector=app.kubernetes.io/name=percona-xtradb-cluster-operator -o 'jsonpath={.items[].metadata.name}' -n pxc-operator +++ mktemp ++ local LAST_OUT=/tmp/tmp.QrBhr4RvBm +++ mktemp ++ local LAST_ERR=/tmp/tmp.CKF5hgGwac ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl get pods --selector=app.kubernetes.io/name=percona-xtradb-cluster-operator -o 'jsonpath={.items[].metadata.name}' -n pxc-operator ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.QrBhr4RvBm ++ cat /tmp/tmp.CKF5hgGwac ++ rm /tmp/tmp.QrBhr4RvBm /tmp/tmp.CKF5hgGwac ++ return 0 + wait_pod percona-xtradb-cluster-operator-5699d7755d-xqvwd 480 pxc-operator + local pod=percona-xtradb-cluster-operator-5699d7755d-xqvwd + local max_retry=480 + local ns=pxc-operator ++ echo percona-xtradb-cluster-operator-5699d7755d-xqvwd ++ /usr/bin/sed -E 's/.*-(pxc|proxysql)-[0-9]/\1/' ++ egrep '^(pxc|proxysql)$' + local container= + set +o xtrace percona-xtradb-cluster-operator-5699d7755d-xqvwd.Ok + sleep 3 + create_namespace tls-issue-cert-manager-11948 + local namespace=tls-issue-cert-manager-11948 + local skip_clean_namespace= + [[ 1 == 1 ]] + [[ -z '' ]] + egrep -v '^kube-|^default|Terminating|pxc-operator|openshift|^NAME' + '[' '!' -z '' ']' + kubectl_bin delete namespace tls-issue-cert-manager-11948 + kubectl_bin get ns ++ mktemp + awk '{print$1}' + xargs kubectl delete ns + local LAST_OUT=/tmp/tmp.WPlI8OUc0U ++ mktemp ++ mktemp + local LAST_ERR=/tmp/tmp.AzZFfis4pN + local exit_status=0 ++ seq 0 2 + local LAST_OUT=/tmp/tmp.RwaWdfCfu2 ++ mktemp + for i in '$(seq 0 2)' + kubectl get ns + local LAST_ERR=/tmp/tmp.uhaira1vcj + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl delete namespace tls-issue-cert-manager-11948 + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.WPlI8OUc0U + cat /tmp/tmp.AzZFfis4pN + rm /tmp/tmp.WPlI8OUc0U /tmp/tmp.AzZFfis4pN + return 0 + exit_status=1 + [[ 1 != 0 ]] + sleep 0 + for i in '$(seq 0 2)' + kubectl delete namespace tls-issue-cert-manager-11948 error: resource(s) were provided, but no name, label selector, or --all flag specified + exit_status=1 + [[ 1 != 0 ]] + sleep 0 + for i in '$(seq 0 2)' + kubectl delete namespace tls-issue-cert-manager-11948 + exit_status=1 + [[ 1 != 0 ]] + sleep 0 + cat /tmp/tmp.RwaWdfCfu2 + cat /tmp/tmp.uhaira1vcj Error from server (NotFound): namespaces "tls-issue-cert-manager-11948" not found + rm /tmp/tmp.RwaWdfCfu2 /tmp/tmp.uhaira1vcj + return 1 + : + wait_for_delete namespace/tls-issue-cert-manager-11948 + local res=namespace/tls-issue-cert-manager-11948 + set +o xtrace namespace/tls-issue-cert-manager-11948 - Error from server (NotFound): namespaces "tls-issue-cert-manager-11948" not found + kubectl_bin create namespace tls-issue-cert-manager-11948 ++ mktemp + local LAST_OUT=/tmp/tmp.tpTCSFzMeb ++ mktemp + local LAST_ERR=/tmp/tmp.FcVEGPnVkG + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl create namespace tls-issue-cert-manager-11948 + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.tpTCSFzMeb namespace/tls-issue-cert-manager-11948 created + cat /tmp/tmp.FcVEGPnVkG + rm /tmp/tmp.tpTCSFzMeb /tmp/tmp.FcVEGPnVkG + return 0 ++ kubectl_bin config current-context +++ mktemp ++ local LAST_OUT=/tmp/tmp.YNf4Ta0xa9 +++ mktemp ++ local LAST_ERR=/tmp/tmp.D6bXTuFWx0 ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl config current-context ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.YNf4Ta0xa9 ++ cat /tmp/tmp.D6bXTuFWx0 ++ rm /tmp/tmp.YNf4Ta0xa9 /tmp/tmp.D6bXTuFWx0 ++ return 0 + kubectl_bin config set-context gke_cloud-dev-112233_us-central1-a_jenkins-pxc-706f792a-basic --namespace=tls-issue-cert-manager-11948 ++ mktemp + local LAST_OUT=/tmp/tmp.vZHR6Lx5rv ++ mktemp + local LAST_ERR=/tmp/tmp.yOzsZK8j9R + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl config set-context gke_cloud-dev-112233_us-central1-a_jenkins-pxc-706f792a-basic --namespace=tls-issue-cert-manager-11948 + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.vZHR6Lx5rv Context "gke_cloud-dev-112233_us-central1-a_jenkins-pxc-706f792a-basic" modified. + cat /tmp/tmp.yOzsZK8j9R + rm /tmp/tmp.vZHR6Lx5rv /tmp/tmp.yOzsZK8j9R + return 0 + apply_secrets + '[' -z '' ']' + kubectl_bin apply -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/conf/minio-secret.yml -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/conf/cloud-secret.yml ++ mktemp + local LAST_OUT=/tmp/tmp.UKCSaLSRnM ++ mktemp + local LAST_ERR=/tmp/tmp.Ab03EzQuSY + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl apply -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/conf/minio-secret.yml -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/conf/cloud-secret.yml + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.UKCSaLSRnM secret/minio-secret created secret/aws-s3-secret created secret/gcp-cs-secret created secret/azure-secret created + cat /tmp/tmp.Ab03EzQuSY + rm /tmp/tmp.UKCSaLSRnM /tmp/tmp.Ab03EzQuSY + return 0 + cluster=some-name-tls-issue + desc 'deploy cert manager' + set +o xtrace ----------------------------------------------------------------------------------- deploy cert manager ----------------------------------------------------------------------------------- + deploy_cert_manager + kubectl_bin create namespace cert-manager ++ mktemp + local LAST_OUT=/tmp/tmp.U9mqelqei5 ++ mktemp + local LAST_ERR=/tmp/tmp.HzwZNdUCV6 + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl create namespace cert-manager + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.U9mqelqei5 namespace/cert-manager created + cat /tmp/tmp.HzwZNdUCV6 + rm /tmp/tmp.U9mqelqei5 /tmp/tmp.HzwZNdUCV6 + return 0 + kubectl_bin label namespace cert-manager certmanager.k8s.io/disable-validation=true ++ mktemp + local LAST_OUT=/tmp/tmp.NCtotv76NW ++ mktemp + local LAST_ERR=/tmp/tmp.gVWq5990pR + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl label namespace cert-manager certmanager.k8s.io/disable-validation=true + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.NCtotv76NW namespace/cert-manager labeled + cat /tmp/tmp.gVWq5990pR + rm /tmp/tmp.NCtotv76NW /tmp/tmp.gVWq5990pR + return 0 + kubectl_bin apply -f https://github.com/jetstack/cert-manager/releases/download/v1.5.4/cert-manager.yaml --validate=false ++ mktemp + local LAST_OUT=/tmp/tmp.SFuFjVWczt ++ mktemp + local LAST_ERR=/tmp/tmp.z9L0PKu8MC + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl apply -f https://github.com/jetstack/cert-manager/releases/download/v1.5.4/cert-manager.yaml --validate=false + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.SFuFjVWczt customresourcedefinition.apiextensions.k8s.io/certificaterequests.cert-manager.io created customresourcedefinition.apiextensions.k8s.io/certificates.cert-manager.io created customresourcedefinition.apiextensions.k8s.io/challenges.acme.cert-manager.io created customresourcedefinition.apiextensions.k8s.io/clusterissuers.cert-manager.io created customresourcedefinition.apiextensions.k8s.io/issuers.cert-manager.io created customresourcedefinition.apiextensions.k8s.io/orders.acme.cert-manager.io created namespace/cert-manager configured serviceaccount/cert-manager-cainjector created serviceaccount/cert-manager created serviceaccount/cert-manager-webhook created clusterrole.rbac.authorization.k8s.io/cert-manager-cainjector created clusterrole.rbac.authorization.k8s.io/cert-manager-controller-issuers created clusterrole.rbac.authorization.k8s.io/cert-manager-controller-clusterissuers created clusterrole.rbac.authorization.k8s.io/cert-manager-controller-certificates created clusterrole.rbac.authorization.k8s.io/cert-manager-controller-orders created clusterrole.rbac.authorization.k8s.io/cert-manager-controller-challenges created clusterrole.rbac.authorization.k8s.io/cert-manager-controller-ingress-shim created clusterrole.rbac.authorization.k8s.io/cert-manager-view created clusterrole.rbac.authorization.k8s.io/cert-manager-edit created clusterrole.rbac.authorization.k8s.io/cert-manager-controller-approve:cert-manager-io created clusterrole.rbac.authorization.k8s.io/cert-manager-controller-certificatesigningrequests created clusterrole.rbac.authorization.k8s.io/cert-manager-webhook:subjectaccessreviews created clusterrolebinding.rbac.authorization.k8s.io/cert-manager-cainjector created clusterrolebinding.rbac.authorization.k8s.io/cert-manager-controller-issuers created clusterrolebinding.rbac.authorization.k8s.io/cert-manager-controller-clusterissuers created clusterrolebinding.rbac.authorization.k8s.io/cert-manager-controller-certificates created clusterrolebinding.rbac.authorization.k8s.io/cert-manager-controller-orders created clusterrolebinding.rbac.authorization.k8s.io/cert-manager-controller-challenges created clusterrolebinding.rbac.authorization.k8s.io/cert-manager-controller-ingress-shim created clusterrolebinding.rbac.authorization.k8s.io/cert-manager-controller-approve:cert-manager-io created clusterrolebinding.rbac.authorization.k8s.io/cert-manager-controller-certificatesigningrequests created clusterrolebinding.rbac.authorization.k8s.io/cert-manager-webhook:subjectaccessreviews created role.rbac.authorization.k8s.io/cert-manager-cainjector:leaderelection created role.rbac.authorization.k8s.io/cert-manager:leaderelection created role.rbac.authorization.k8s.io/cert-manager-webhook:dynamic-serving created rolebinding.rbac.authorization.k8s.io/cert-manager-cainjector:leaderelection created rolebinding.rbac.authorization.k8s.io/cert-manager:leaderelection created rolebinding.rbac.authorization.k8s.io/cert-manager-webhook:dynamic-serving created service/cert-manager created service/cert-manager-webhook created deployment.apps/cert-manager-cainjector created deployment.apps/cert-manager created deployment.apps/cert-manager-webhook created mutatingwebhookconfiguration.admissionregistration.k8s.io/cert-manager-webhook created validatingwebhookconfiguration.admissionregistration.k8s.io/cert-manager-webhook created + cat /tmp/tmp.z9L0PKu8MC Warning: resource namespaces/cert-manager is missing the kubectl.kubernetes.io/last-applied-configuration annotation which is required by kubectl apply. kubectl apply should only be used on resources created declaratively by either kubectl create --save-config or kubectl apply. The missing annotation will be patched automatically. + rm /tmp/tmp.SFuFjVWczt /tmp/tmp.z9L0PKu8MC + return 0 + sleep 60 + desc 'create pxc cluster' + set +o xtrace ----------------------------------------------------------------------------------- create pxc cluster ----------------------------------------------------------------------------------- + spinup_pxc some-name-tls-issue /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/some-name-tls-issue.yml 3 10 /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/conf/secrets_without_tls.yml /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/client.yml + local cluster=some-name-tls-issue + local config=/mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/some-name-tls-issue.yml + local size=3 + local sleep=10 + local secretsFile=/mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/conf/secrets_without_tls.yml + local pxcClientFile=/mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/client.yml + desc 'create first PXC cluster' + set +o xtrace ----------------------------------------------------------------------------------- create first PXC cluster ----------------------------------------------------------------------------------- + kubectl_bin apply -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/conf/secrets_without_tls.yml ++ mktemp + local LAST_OUT=/tmp/tmp.Qz1BETYPEQ ++ mktemp + local LAST_ERR=/tmp/tmp.HelopPGHAM + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl apply -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/conf/secrets_without_tls.yml + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.Qz1BETYPEQ secret/my-cluster-secrets created + cat /tmp/tmp.HelopPGHAM + rm /tmp/tmp.Qz1BETYPEQ /tmp/tmp.HelopPGHAM + return 0 + apply_config /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/client.yml + '[' -z '' ']' + cat_config /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/client.yml + kubectl_bin apply -f - + cat /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/client.yml + /usr/bin/sed -e 's#image:.*\/percona-xtradb-cluster:.*$#image: perconalab/percona-xtradb-cluster-operator:main-pxc8.0#' ++ mktemp + /usr/bin/sed -e 's#apply:.*#apply: Never#' + /usr/bin/sed -e 's#initImage:.*-init$#initImage: perconalab/percona-xtradb-cluster-operator:PR-1125-706f792a#' + /usr/bin/sed -e 's#image:.*-pmm$#image: perconalab/pmm-client:dev-latest#' + /usr/bin/sed -e 's#image:.*-backup$#image: perconalab/percona-xtradb-cluster-operator:main-pxc8.0-backup#' + /usr/bin/sed -e s~minio-service.#namespace~minio-service.tls-issue-cert-manager-11948~ + /usr/bin/sed -e 's#image:.*-proxysql$#image: perconalab/percona-xtradb-cluster-operator:main-proxysql#' + /usr/bin/sed -e 's#image:.*-pxc\([0-9]*.[0-9]*\)\{0,1\}$#image: perconalab/percona-xtradb-cluster-operator:main-pxc8.0#' + local LAST_OUT=/tmp/tmp.EnyeBdjEsX + /usr/bin/sed -e 's#image:.*-haproxy$#image: perconalab/percona-xtradb-cluster-operator:main-haproxy#' + /usr/bin/sed -e 's#image:.*-logcollector$#image: perconalab/percona-xtradb-cluster-operator:main-logcollector#' + /usr/bin/sed -e 's#apiVersion: pxc.percona.com/v.*$#apiVersion: pxc.percona.com/v1-11-0#' ++ mktemp + local LAST_ERR=/tmp/tmp.IraWSZeLYF + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl apply -f - + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.EnyeBdjEsX deployment.apps/pxc-client created + cat /tmp/tmp.IraWSZeLYF + rm /tmp/tmp.EnyeBdjEsX /tmp/tmp.IraWSZeLYF + return 0 + [[ perconalab/percona-xtradb-cluster-operator:main-pxc8.0 =~ 5\.7 ]] + apply_config /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/some-name-tls-issue.yml + '[' -z '' ']' + kubectl_bin apply -f - + cat_config /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/some-name-tls-issue.yml ++ mktemp + /usr/bin/sed -e 's#apiVersion: pxc.percona.com/v.*$#apiVersion: pxc.percona.com/v1-11-0#' + /usr/bin/sed -e 's#image:.*-pxc\([0-9]*.[0-9]*\)\{0,1\}$#image: perconalab/percona-xtradb-cluster-operator:main-pxc8.0#' + /usr/bin/sed -e 's#initImage:.*-init$#initImage: perconalab/percona-xtradb-cluster-operator:PR-1125-706f792a#' + /usr/bin/sed -e 's#image:.*-pmm$#image: perconalab/pmm-client:dev-latest#' + local LAST_OUT=/tmp/tmp.GPPRD1X312 + /usr/bin/sed -e 's#image:.*-proxysql$#image: perconalab/percona-xtradb-cluster-operator:main-proxysql#' + /usr/bin/sed -e 's#image:.*-logcollector$#image: perconalab/percona-xtradb-cluster-operator:main-logcollector#' + /usr/bin/sed -e s~minio-service.#namespace~minio-service.tls-issue-cert-manager-11948~ + /usr/bin/sed -e 's#image:.*-haproxy$#image: perconalab/percona-xtradb-cluster-operator:main-haproxy#' + /usr/bin/sed -e 's#image:.*-backup$#image: perconalab/percona-xtradb-cluster-operator:main-pxc8.0-backup#' ++ mktemp + /usr/bin/sed -e 's#apply:.*#apply: Never#' + /usr/bin/sed -e 's#image:.*\/percona-xtradb-cluster:.*$#image: perconalab/percona-xtradb-cluster-operator:main-pxc8.0#' + cat /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/some-name-tls-issue.yml + local LAST_ERR=/tmp/tmp.Po514pMd3Z + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl apply -f - + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.GPPRD1X312 perconaxtradbcluster.pxc.percona.com/some-name-tls-issue created + cat /tmp/tmp.Po514pMd3Z + rm /tmp/tmp.GPPRD1X312 /tmp/tmp.Po514pMd3Z + return 0 + desc 'check if all 3 Pods started' + set +o xtrace ----------------------------------------------------------------------------------- check if all 3 Pods started ----------------------------------------------------------------------------------- ++ get_proxy some-name-tls-issue ++ local target_cluster=some-name-tls-issue +++ kubectl_bin get pxc some-name-tls-issue -o 'jsonpath={.spec.haproxy.enabled}' ++++ mktemp +++ local LAST_OUT=/tmp/tmp.BQblIlBUoW ++++ mktemp +++ local LAST_ERR=/tmp/tmp.QC7eHU6YKg +++ local exit_status=0 ++++ seq 0 2 +++ for i in '$(seq 0 2)' +++ kubectl get pxc some-name-tls-issue -o 'jsonpath={.spec.haproxy.enabled}' +++ exit_status=0 +++ [[ 0 != 0 ]] +++ break +++ cat /tmp/tmp.BQblIlBUoW +++ cat /tmp/tmp.QC7eHU6YKg +++ rm /tmp/tmp.BQblIlBUoW /tmp/tmp.QC7eHU6YKg +++ return 0 ++ [[ '' == \t\r\u\e ]] +++ kubectl_bin get pxc some-name-tls-issue -o 'jsonpath={.spec.proxysql.enabled}' ++++ mktemp +++ local LAST_OUT=/tmp/tmp.35kGvBLWSH ++++ mktemp +++ local LAST_ERR=/tmp/tmp.OKiubjDdDq +++ local exit_status=0 ++++ seq 0 2 +++ for i in '$(seq 0 2)' +++ kubectl get pxc some-name-tls-issue -o 'jsonpath={.spec.proxysql.enabled}' +++ exit_status=0 +++ [[ 0 != 0 ]] +++ break +++ cat /tmp/tmp.35kGvBLWSH +++ cat /tmp/tmp.OKiubjDdDq +++ rm /tmp/tmp.35kGvBLWSH /tmp/tmp.OKiubjDdDq +++ return 0 ++ [[ true == \t\r\u\e ]] ++ echo some-name-tls-issue-proxysql ++ return + local proxy=some-name-tls-issue-proxysql + wait_for_running some-name-tls-issue-proxysql 1 + local name=some-name-tls-issue-proxysql + let last_pod=0 + : + local max_retry=480 ++ seq 0 0 + for i in '$(seq 0 $last_pod)' + wait_pod some-name-tls-issue-proxysql-0 480 + local pod=some-name-tls-issue-proxysql-0 + local max_retry=480 + local ns= ++ echo some-name-tls-issue-proxysql-0 ++ /usr/bin/sed -E 's/.*-(pxc|proxysql)-[0-9]/\1/' ++ egrep '^(pxc|proxysql)$' + local container=proxysql + set +o xtrace some-name-tls-issue-proxysql-0............Ok + wait_for_running some-name-tls-issue-pxc 3 + local name=some-name-tls-issue-pxc + let last_pod=2 + local max_retry=480 ++ seq 0 2 + for i in '$(seq 0 $last_pod)' + wait_pod some-name-tls-issue-pxc-0 480 + local pod=some-name-tls-issue-pxc-0 + local max_retry=480 + local ns= ++ echo some-name-tls-issue-pxc-0 ++ egrep '^(pxc|proxysql)$' ++ /usr/bin/sed -E 's/.*-(pxc|proxysql)-[0-9]/\1/' + local container=pxc + set +o xtrace some-name-tls-issue-pxc-0......................Ok + for i in '$(seq 0 $last_pod)' + wait_pod some-name-tls-issue-pxc-1 480 + local pod=some-name-tls-issue-pxc-1 + local max_retry=480 + local ns= ++ echo some-name-tls-issue-pxc-1 ++ /usr/bin/sed -E 's/.*-(pxc|proxysql)-[0-9]/\1/' ++ egrep '^(pxc|proxysql)$' + local container=pxc + set +o xtrace some-name-tls-issue-pxc-1......................................Ok + for i in '$(seq 0 $last_pod)' + wait_pod some-name-tls-issue-pxc-2 480 + local pod=some-name-tls-issue-pxc-2 + local max_retry=480 + local ns= ++ echo some-name-tls-issue-pxc-2 ++ /usr/bin/sed -E 's/.*-(pxc|proxysql)-[0-9]/\1/' ++ egrep '^(pxc|proxysql)$' + local container=pxc + set +o xtrace some-name-tls-issue-pxc-2........................................Ok + sleep 10 + desc 'write data' + set +o xtrace ----------------------------------------------------------------------------------- write data ----------------------------------------------------------------------------------- + [[ perconalab/percona-xtradb-cluster-operator:main-pxc8.0 =~ 5\.7 ]] + run_mysql 'CREATE DATABASE IF NOT EXISTS myApp; use myApp; CREATE TABLE IF NOT EXISTS myApp (id int PRIMARY KEY) ;' '-h some-name-tls-issue-proxysql -uroot -proot_password' + local 'command=CREATE DATABASE IF NOT EXISTS myApp; use myApp; CREATE TABLE IF NOT EXISTS myApp (id int PRIMARY KEY) ;' + local 'uri=-h some-name-tls-issue-proxysql -uroot -proot_password' ++ get_client_pod ++ kubectl_bin get pods --selector=name=pxc-client -o 'jsonpath={.items[].metadata.name}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.94CIIwGRSu +++ mktemp ++ local LAST_ERR=/tmp/tmp.savGvqr04B ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl get pods --selector=name=pxc-client -o 'jsonpath={.items[].metadata.name}' ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.94CIIwGRSu ++ cat /tmp/tmp.savGvqr04B ++ rm /tmp/tmp.94CIIwGRSu /tmp/tmp.savGvqr04B ++ return 0 + client_pod=pxc-client-d75b94bf6-l7q74 + wait_pod pxc-client-d75b94bf6-l7q74 + local pod=pxc-client-d75b94bf6-l7q74 + local max_retry=480 + local ns= ++ echo pxc-client-d75b94bf6-l7q74 ++ /usr/bin/sed -E 's/.*-(pxc|proxysql)-[0-9]/\1/' ++ egrep '^(pxc|proxysql)$' + local container= + set +o xtrace pxc-client-d75b94bf6-l7q74.Ok + set +o xtrace + run_mysql 'INSERT myApp.myApp (id) VALUES (100500)' '-h some-name-tls-issue-proxysql -uroot -proot_password' + local 'command=INSERT myApp.myApp (id) VALUES (100500)' + local 'uri=-h some-name-tls-issue-proxysql -uroot -proot_password' ++ get_client_pod ++ kubectl_bin get pods --selector=name=pxc-client -o 'jsonpath={.items[].metadata.name}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.MfDQMelom3 +++ mktemp ++ local LAST_ERR=/tmp/tmp.zRyrIlKDSY ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl get pods --selector=name=pxc-client -o 'jsonpath={.items[].metadata.name}' ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.MfDQMelom3 ++ cat /tmp/tmp.zRyrIlKDSY ++ rm /tmp/tmp.MfDQMelom3 /tmp/tmp.zRyrIlKDSY ++ return 0 + client_pod=pxc-client-d75b94bf6-l7q74 + wait_pod pxc-client-d75b94bf6-l7q74 + local pod=pxc-client-d75b94bf6-l7q74 + local max_retry=480 + local ns= ++ echo pxc-client-d75b94bf6-l7q74 ++ /usr/bin/sed -E 's/.*-(pxc|proxysql)-[0-9]/\1/' ++ egrep '^(pxc|proxysql)$' + local container= + set +o xtrace pxc-client-d75b94bf6-l7q74.Ok + set +o xtrace + sleep 30 ++ seq 0 2 + for i in '$(seq 0 $((size - 1)))' + compare_mysql_cmd select-1 'SELECT * from myApp.myApp;' '-h some-name-tls-issue-pxc-0.some-name-tls-issue-pxc -uroot -proot_password' + local command_id=select-1 + local 'command=SELECT * from myApp.myApp;' + local 'uri=-h some-name-tls-issue-pxc-0.some-name-tls-issue-pxc -uroot -proot_password' + local postfix= + local expected_result=/mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/select-1.sql + [[ perconalab/percona-xtradb-cluster-operator:main-pxc8.0 =~ 8\.0 ]] + '[' -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/select-1-80.sql ']' + run_mysql 'SELECT * from myApp.myApp;' '-h some-name-tls-issue-pxc-0.some-name-tls-issue-pxc -uroot -proot_password' + local 'command=SELECT * from myApp.myApp;' + local 'uri=-h some-name-tls-issue-pxc-0.some-name-tls-issue-pxc -uroot -proot_password' ++ get_client_pod ++ kubectl_bin get pods --selector=name=pxc-client -o 'jsonpath={.items[].metadata.name}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.MVZ5WgP8nJ +++ mktemp ++ local LAST_ERR=/tmp/tmp.YjSn2l3gtl ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl get pods --selector=name=pxc-client -o 'jsonpath={.items[].metadata.name}' ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.MVZ5WgP8nJ ++ cat /tmp/tmp.YjSn2l3gtl ++ rm /tmp/tmp.MVZ5WgP8nJ /tmp/tmp.YjSn2l3gtl ++ return 0 + client_pod=pxc-client-d75b94bf6-l7q74 + wait_pod pxc-client-d75b94bf6-l7q74 + local pod=pxc-client-d75b94bf6-l7q74 + local max_retry=480 + local ns= ++ echo pxc-client-d75b94bf6-l7q74 ++ /usr/bin/sed -E 's/.*-(pxc|proxysql)-[0-9]/\1/' ++ egrep '^(pxc|proxysql)$' + local container= + set +o xtrace pxc-client-d75b94bf6-l7q74.Ok + set +o xtrace + '[' '!' -s /tmp/tmp.RPSg5CpXRe/select-1.sql ']' + diff -u /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/select-1.sql /tmp/tmp.RPSg5CpXRe/select-1.sql + for i in '$(seq 0 $((size - 1)))' + compare_mysql_cmd select-1 'SELECT * from myApp.myApp;' '-h some-name-tls-issue-pxc-1.some-name-tls-issue-pxc -uroot -proot_password' + local command_id=select-1 + local 'command=SELECT * from myApp.myApp;' + local 'uri=-h some-name-tls-issue-pxc-1.some-name-tls-issue-pxc -uroot -proot_password' + local postfix= + local expected_result=/mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/select-1.sql + [[ perconalab/percona-xtradb-cluster-operator:main-pxc8.0 =~ 8\.0 ]] + '[' -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/select-1-80.sql ']' + run_mysql 'SELECT * from myApp.myApp;' '-h some-name-tls-issue-pxc-1.some-name-tls-issue-pxc -uroot -proot_password' + local 'command=SELECT * from myApp.myApp;' + local 'uri=-h some-name-tls-issue-pxc-1.some-name-tls-issue-pxc -uroot -proot_password' ++ get_client_pod ++ kubectl_bin get pods --selector=name=pxc-client -o 'jsonpath={.items[].metadata.name}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.A8UvRoHzOL +++ mktemp ++ local LAST_ERR=/tmp/tmp.wq7zDxOOuS ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl get pods --selector=name=pxc-client -o 'jsonpath={.items[].metadata.name}' ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.A8UvRoHzOL ++ cat /tmp/tmp.wq7zDxOOuS ++ rm /tmp/tmp.A8UvRoHzOL /tmp/tmp.wq7zDxOOuS ++ return 0 + client_pod=pxc-client-d75b94bf6-l7q74 + wait_pod pxc-client-d75b94bf6-l7q74 + local pod=pxc-client-d75b94bf6-l7q74 + local max_retry=480 + local ns= ++ echo pxc-client-d75b94bf6-l7q74 ++ /usr/bin/sed -E 's/.*-(pxc|proxysql)-[0-9]/\1/' ++ egrep '^(pxc|proxysql)$' + local container= + set +o xtrace pxc-client-d75b94bf6-l7q74.Ok + set +o xtrace + '[' '!' -s /tmp/tmp.RPSg5CpXRe/select-1.sql ']' + diff -u /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/select-1.sql /tmp/tmp.RPSg5CpXRe/select-1.sql + for i in '$(seq 0 $((size - 1)))' + compare_mysql_cmd select-1 'SELECT * from myApp.myApp;' '-h some-name-tls-issue-pxc-2.some-name-tls-issue-pxc -uroot -proot_password' + local command_id=select-1 + local 'command=SELECT * from myApp.myApp;' + local 'uri=-h some-name-tls-issue-pxc-2.some-name-tls-issue-pxc -uroot -proot_password' + local postfix= + local expected_result=/mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/select-1.sql + [[ perconalab/percona-xtradb-cluster-operator:main-pxc8.0 =~ 8\.0 ]] + '[' -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/select-1-80.sql ']' + run_mysql 'SELECT * from myApp.myApp;' '-h some-name-tls-issue-pxc-2.some-name-tls-issue-pxc -uroot -proot_password' + local 'command=SELECT * from myApp.myApp;' + local 'uri=-h some-name-tls-issue-pxc-2.some-name-tls-issue-pxc -uroot -proot_password' ++ get_client_pod ++ kubectl_bin get pods --selector=name=pxc-client -o 'jsonpath={.items[].metadata.name}' +++ mktemp ++ local LAST_OUT=/tmp/tmp.IDqHkyG7M9 +++ mktemp ++ local LAST_ERR=/tmp/tmp.iC15jtiQc4 ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl get pods --selector=name=pxc-client -o 'jsonpath={.items[].metadata.name}' ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.IDqHkyG7M9 ++ cat /tmp/tmp.iC15jtiQc4 ++ rm /tmp/tmp.IDqHkyG7M9 /tmp/tmp.iC15jtiQc4 ++ return 0 + client_pod=pxc-client-d75b94bf6-l7q74 + wait_pod pxc-client-d75b94bf6-l7q74 + local pod=pxc-client-d75b94bf6-l7q74 + local max_retry=480 + local ns= ++ echo pxc-client-d75b94bf6-l7q74 ++ /usr/bin/sed -E 's/.*-(pxc|proxysql)-[0-9]/\1/' ++ egrep '^(pxc|proxysql)$' + local container= + set +o xtrace pxc-client-d75b94bf6-l7q74.Ok + set +o xtrace + '[' '!' -s /tmp/tmp.RPSg5CpXRe/select-1.sql ']' + diff -u /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/select-1.sql /tmp/tmp.RPSg5CpXRe/select-1.sql ++ is_keyring_plugin_in_use some-name-tls-issue ++ local cluster=some-name-tls-issue ++ kubectl_bin exec -it some-name-tls-issue-pxc-0 -c pxc -- bash -c 'cat /etc/mysql/node.cnf' ++ egrep -o 'early-plugin-load=keyring_\w+.so' +++ mktemp ++ local LAST_OUT=/tmp/tmp.OhOG1XrAOK +++ mktemp ++ local LAST_ERR=/tmp/tmp.Clos6rpXEo ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl exec -it some-name-tls-issue-pxc-0 -c pxc -- bash -c 'cat /etc/mysql/node.cnf' ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.OhOG1XrAOK ++ cat /tmp/tmp.Clos6rpXEo Unable to use a TTY - input is not a terminal or the right kind of file ++ rm /tmp/tmp.OhOG1XrAOK /tmp/tmp.Clos6rpXEo ++ return 0 + '[' '' ']' + desc 'check if certificates issued with certmanager' + set +o xtrace ----------------------------------------------------------------------------------- check if certificates issued with certmanager ----------------------------------------------------------------------------------- + tlsSecretsShouldExist some-name-tls-issue-ssl + local secretName=some-name-tls-issue-ssl + checkTLSSecret some-name-tls-issue-ssl ca.crt + local secretName=some-name-tls-issue-ssl + local dataKey=ca.crt ++ kubectl_bin get secrets/some-name-tls-issue-ssl -o json ++ jq '.data["ca.crt"]' +++ mktemp ++ local LAST_OUT=/tmp/tmp.tXvHKDeau3 +++ mktemp ++ local LAST_ERR=/tmp/tmp.jXkKIxAX3C ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl get secrets/some-name-tls-issue-ssl -o json ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.tXvHKDeau3 ++ cat /tmp/tmp.jXkKIxAX3C ++ rm /tmp/tmp.tXvHKDeau3 /tmp/tmp.jXkKIxAX3C ++ return 0 + local 'secretData="LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUREekNDQWZlZ0F3SUJBZ0lSQU41K0RQdlB6OU8xLzZoUm9QeUVqVGd3RFFZSktvWklodmNOQVFFTEJRQXcKSVRFZk1CMEdBMVVFQXhNV2MyOXRaUzF1WVcxbExYUnNjeTFwYzNOMVpTMWpZVEFlRncweU1qQTBNVEl4TXpNdwpORGxhRncwek1qQTBNRGt4TXpNd05EbGFNQ0V4SHpBZEJnTlZCQU1URm5OdmJXVXRibUZ0WlMxMGJITXRhWE56CmRXVXRZMkV3Z2dFaU1BMEdDU3FHU0liM0RRRUJBUVVBQTRJQkR3QXdnZ0VLQW9JQkFRQytEMXZXdUd2dU90UVMKQS80MzQwU1RvOTIrSUh0K1dIeGpDNHRTYUJHL2NHM2dGeWJhNzVseG81bXJzMklpNG5ZQVZBNEYvVFhKekZiKwprUEVxb1RnWmFUL0hJRUlkZXFOMU1CL1U2U3pDZHdnSWJGTTlDdjRBNmZFaWU1WDN1NVZXeVNmSEVYSGxlT2ZwCnp6TnZuZjRLQUNHcjdWWEJqZEE0cnFncHVIaXhoc2tLZGhXQ3dGMDlTVjNLK0o5WnhVNVhmS1hhTnNYMTZ5cDIKV2h1UmFpUkJSZkdvRlZGQ3Bib09lc1ZVZWJlMFJEY1JNZEh5M2M3K1RidjcvcXh0b3RiK3VneEJRVmY5MkU4UQpucXZiZzBONWgyM0Nnbm01d3EvMW5KUUMrdk1xNkpZc1RBYytPcTNIYjhQeUNjQ25MWDhSTXlMcFVGckRZaFZOCmFGWU91TVpEQWdNQkFBR2pRakJBTUE0R0ExVWREd0VCL3dRRUF3SUNwREFQQmdOVkhSTUJBZjhFQlRBREFRSC8KTUIwR0ExVWREZ1FXQkJSNEUxdU92L0xCcUU4bnBSdnk2ZjV6V0lpMDJUQU5CZ2txaGtpRzl3MEJBUXNGQUFPQwpBUUVBZHB3azJBQ2FpT3VjRWR0YVRQY24rb0d3WG1uK0Vxd1k3WVZXejhKcU9PaHg2TDhvS2hNVVVjamp6TnZTCm9LcjhsYkkzeFVHcTQzZVJ3YWdDWkRlOEpwakk5WmZPNGxHWDdWd2NRNWxEMEVIS0NMRXV2LzhaVTlUY1F5NzUKdktSRVlSanNWSk4veThhdmpGb1RwamxLK2FBY1ZhN01LQURsdisyVWdZLytZNWRtSmF3UGNqMTJGRnhVL2c4ZwpqNzI5ZWlBYWFBYVcwOVFXa0Y0eDBvVG9EZUNxNytUN1JEeVJvSElMbXFMTDMvYW5zK0pzQkdZWUFWb3Fwd3RSCnBGL0lnaTlnY1k5aFpoZHRqNmN6OWdlcTZuQVl5d1V3OTVrM2xKQ0o5NUlKWWJoMlYwY1dESVFwbDJqaDdXWU0KUjhpSUlkNzdSNjdNcElmN2k3V1NXdHZ2QXc9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg=="' + '[' -z '"LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUREekNDQWZlZ0F3SUJBZ0lSQU41K0RQdlB6OU8xLzZoUm9QeUVqVGd3RFFZSktvWklodmNOQVFFTEJRQXcKSVRFZk1CMEdBMVVFQXhNV2MyOXRaUzF1WVcxbExYUnNjeTFwYzNOMVpTMWpZVEFlRncweU1qQTBNVEl4TXpNdwpORGxhRncwek1qQTBNRGt4TXpNd05EbGFNQ0V4SHpBZEJnTlZCQU1URm5OdmJXVXRibUZ0WlMxMGJITXRhWE56CmRXVXRZMkV3Z2dFaU1BMEdDU3FHU0liM0RRRUJBUVVBQTRJQkR3QXdnZ0VLQW9JQkFRQytEMXZXdUd2dU90UVMKQS80MzQwU1RvOTIrSUh0K1dIeGpDNHRTYUJHL2NHM2dGeWJhNzVseG81bXJzMklpNG5ZQVZBNEYvVFhKekZiKwprUEVxb1RnWmFUL0hJRUlkZXFOMU1CL1U2U3pDZHdnSWJGTTlDdjRBNmZFaWU1WDN1NVZXeVNmSEVYSGxlT2ZwCnp6TnZuZjRLQUNHcjdWWEJqZEE0cnFncHVIaXhoc2tLZGhXQ3dGMDlTVjNLK0o5WnhVNVhmS1hhTnNYMTZ5cDIKV2h1UmFpUkJSZkdvRlZGQ3Bib09lc1ZVZWJlMFJEY1JNZEh5M2M3K1RidjcvcXh0b3RiK3VneEJRVmY5MkU4UQpucXZiZzBONWgyM0Nnbm01d3EvMW5KUUMrdk1xNkpZc1RBYytPcTNIYjhQeUNjQ25MWDhSTXlMcFVGckRZaFZOCmFGWU91TVpEQWdNQkFBR2pRakJBTUE0R0ExVWREd0VCL3dRRUF3SUNwREFQQmdOVkhSTUJBZjhFQlRBREFRSC8KTUIwR0ExVWREZ1FXQkJSNEUxdU92L0xCcUU4bnBSdnk2ZjV6V0lpMDJUQU5CZ2txaGtpRzl3MEJBUXNGQUFPQwpBUUVBZHB3azJBQ2FpT3VjRWR0YVRQY24rb0d3WG1uK0Vxd1k3WVZXejhKcU9PaHg2TDhvS2hNVVVjamp6TnZTCm9LcjhsYkkzeFVHcTQzZVJ3YWdDWkRlOEpwakk5WmZPNGxHWDdWd2NRNWxEMEVIS0NMRXV2LzhaVTlUY1F5NzUKdktSRVlSanNWSk4veThhdmpGb1RwamxLK2FBY1ZhN01LQURsdisyVWdZLytZNWRtSmF3UGNqMTJGRnhVL2c4ZwpqNzI5ZWlBYWFBYVcwOVFXa0Y0eDBvVG9EZUNxNytUN1JEeVJvSElMbXFMTDMvYW5zK0pzQkdZWUFWb3Fwd3RSCnBGL0lnaTlnY1k5aFpoZHRqNmN6OWdlcTZuQVl5d1V3OTVrM2xKQ0o5NUlKWWJoMlYwY1dESVFwbDJqaDdXWU0KUjhpSUlkNzdSNjdNcElmN2k3V1NXdHZ2QXc9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg=="' ']' + checkTLSSecret some-name-tls-issue-ssl tls.crt + local secretName=some-name-tls-issue-ssl + local dataKey=tls.crt ++ kubectl_bin get secrets/some-name-tls-issue-ssl -o json ++ jq '.data["tls.crt"]' +++ mktemp ++ local LAST_OUT=/tmp/tmp.2KmeWLob3V +++ mktemp ++ local LAST_ERR=/tmp/tmp.VutQ1siEZz ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl get secrets/some-name-tls-issue-ssl -o json ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.2KmeWLob3V ++ cat /tmp/tmp.VutQ1siEZz ++ rm /tmp/tmp.2KmeWLob3V /tmp/tmp.VutQ1siEZz ++ return 0 + local 'secretData="LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURvVENDQW9tZ0F3SUJBZ0lSQUtaQmkvdm5NOGFxVXFubXRXOW11SFV3RFFZSktvWklodmNOQVFFTEJRQXcKSVRFZk1CMEdBMVVFQXhNV2MyOXRaUzF1WVcxbExYUnNjeTFwYzNOMVpTMWpZVEFlRncweU1qQTBNVEl4TXpNdwpORGxhRncweU1qQTNNVEV4TXpNd05EbGFNQ2N4SlRBakJnTlZCQU1USEhOdmJXVXRibUZ0WlMxMGJITXRhWE56CmRXVXRjSEp2ZUhsemNXd3dnZ0VpTUEwR0NTcUdTSWIzRFFFQkFRVUFBNElCRHdBd2dnRUtBb0lCQVFEQ29aU20KWis2bDV5SXZWNGt6UkwvT3UrRzFPK1ZucVU5Y0VwUmlsSEpqM1BPUjIwR04yWjJWR1FlNGROUjZINWhCWWVOVgp2M3oyTXVuMnplU29nQXRjSmVNVGVKZUJ4T3hkTWpRdmpaQUd4VFhWdTBCaUg1NVFqQXVGR04vU1NZOVg3cmN6CldGSG41TDNHQ1h1MmJ3NFdlb1d4Ri81STY3dE4rZGlXQlU2S2pQMHZGL1dnSDhxaXFmYkZiYm94dlQxRGN2djIKbGFTbmpOa25RWklIQVlFYUFvSjJSeEFPN1NDSURBL3NoZU9QR2VtVkZzSnBVcEZ6TXpGUUxsaW0waXI3ZXhPWAo4QjRvMExGaTNzdDBVVnNMUG1za3BleUpLOEw3YXJlY0hYelpYTG5SVnN5RUJTQ2lINU9MZjF6QURtelNIUC9wCjJ2eGdsbmhSQUUxeVZEQXhBZ01CQUFHamdjMHdnY293RGdZRFZSMFBBUUgvQkFRREFnS2tNQThHQTFVZEV3RUIKL3dRRk1BTUJBZjh3SFFZRFZSME9CQllFRk1QNnFpa1JKc3lMZFVTUlcvYTZFRHVjcmJ5WE1COEdBMVVkSXdRWQpNQmFBRkhnVFc0Ni84c0dvVHllbEcvTHAvbk5ZaUxUWk1HY0dBMVVkRVFSZ01GNkNGM052YldVdGJtRnRaUzEwCmJITXRhWE56ZFdVdGNIaGpnaGtxTG5OdmJXVXRibUZ0WlMxMGJITXRhWE56ZFdVdGNIaGpnaDRxTG5OdmJXVXQKYm1GdFpTMTBiSE10YVhOemRXVXRjSEp2ZUhsemNXeUNDSFJsYzNRdVkyOXRNQTBHQ1NxR1NJYjNEUUVCQ3dVQQpBNElCQVFBazlHMmpJWkQzVHNVd3A3ejROc0xydk9XeVBvREx5Y1dnT1RLODJwMEJqazdQYVpwdCtQN0RVR2FKCmw5bktSQURaUmVWSUJYUXhzLzE3aUNyVnFCZUh4NnpsNENrc3paZmFYTFpmRVNMSk9VK2VqSG94a1V6L3NVaU0KRGwrNC9YRDAzTi9PTGlxMXFpRXZ6UTRRZ2J2d2hQa3pwNzhMU2I3MDZRUm01OHF0L2dkM0w1TWFjR0N5WnEvaQprVGJ6Umk5SjZvUEZVRmRHb0RWVUhXZmtXbFN0U2c4c3NPTW9jdE5GMTQzS3BXeHpWWmlUNUszMEhtSXpRSG40CndncUJsWkV3V2JsMzNVUTBUM0Z1UVdKZTZ1S3JaQ2YwMmdpY1ZERUNpa3hSZjl0SmRDdXk3L05SdUVuMVdCZ2QKRXJhTVFPNUp4ODBSUkVsb2l0RXRUeGx6YjRNUwotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg=="' + '[' -z '"LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURvVENDQW9tZ0F3SUJBZ0lSQUtaQmkvdm5NOGFxVXFubXRXOW11SFV3RFFZSktvWklodmNOQVFFTEJRQXcKSVRFZk1CMEdBMVVFQXhNV2MyOXRaUzF1WVcxbExYUnNjeTFwYzNOMVpTMWpZVEFlRncweU1qQTBNVEl4TXpNdwpORGxhRncweU1qQTNNVEV4TXpNd05EbGFNQ2N4SlRBakJnTlZCQU1USEhOdmJXVXRibUZ0WlMxMGJITXRhWE56CmRXVXRjSEp2ZUhsemNXd3dnZ0VpTUEwR0NTcUdTSWIzRFFFQkFRVUFBNElCRHdBd2dnRUtBb0lCQVFEQ29aU20KWis2bDV5SXZWNGt6UkwvT3UrRzFPK1ZucVU5Y0VwUmlsSEpqM1BPUjIwR04yWjJWR1FlNGROUjZINWhCWWVOVgp2M3oyTXVuMnplU29nQXRjSmVNVGVKZUJ4T3hkTWpRdmpaQUd4VFhWdTBCaUg1NVFqQXVGR04vU1NZOVg3cmN6CldGSG41TDNHQ1h1MmJ3NFdlb1d4Ri81STY3dE4rZGlXQlU2S2pQMHZGL1dnSDhxaXFmYkZiYm94dlQxRGN2djIKbGFTbmpOa25RWklIQVlFYUFvSjJSeEFPN1NDSURBL3NoZU9QR2VtVkZzSnBVcEZ6TXpGUUxsaW0waXI3ZXhPWAo4QjRvMExGaTNzdDBVVnNMUG1za3BleUpLOEw3YXJlY0hYelpYTG5SVnN5RUJTQ2lINU9MZjF6QURtelNIUC9wCjJ2eGdsbmhSQUUxeVZEQXhBZ01CQUFHamdjMHdnY293RGdZRFZSMFBBUUgvQkFRREFnS2tNQThHQTFVZEV3RUIKL3dRRk1BTUJBZjh3SFFZRFZSME9CQllFRk1QNnFpa1JKc3lMZFVTUlcvYTZFRHVjcmJ5WE1COEdBMVVkSXdRWQpNQmFBRkhnVFc0Ni84c0dvVHllbEcvTHAvbk5ZaUxUWk1HY0dBMVVkRVFSZ01GNkNGM052YldVdGJtRnRaUzEwCmJITXRhWE56ZFdVdGNIaGpnaGtxTG5OdmJXVXRibUZ0WlMxMGJITXRhWE56ZFdVdGNIaGpnaDRxTG5OdmJXVXQKYm1GdFpTMTBiSE10YVhOemRXVXRjSEp2ZUhsemNXeUNDSFJsYzNRdVkyOXRNQTBHQ1NxR1NJYjNEUUVCQ3dVQQpBNElCQVFBazlHMmpJWkQzVHNVd3A3ejROc0xydk9XeVBvREx5Y1dnT1RLODJwMEJqazdQYVpwdCtQN0RVR2FKCmw5bktSQURaUmVWSUJYUXhzLzE3aUNyVnFCZUh4NnpsNENrc3paZmFYTFpmRVNMSk9VK2VqSG94a1V6L3NVaU0KRGwrNC9YRDAzTi9PTGlxMXFpRXZ6UTRRZ2J2d2hQa3pwNzhMU2I3MDZRUm01OHF0L2dkM0w1TWFjR0N5WnEvaQprVGJ6Umk5SjZvUEZVRmRHb0RWVUhXZmtXbFN0U2c4c3NPTW9jdE5GMTQzS3BXeHpWWmlUNUszMEhtSXpRSG40CndncUJsWkV3V2JsMzNVUTBUM0Z1UVdKZTZ1S3JaQ2YwMmdpY1ZERUNpa3hSZjl0SmRDdXk3L05SdUVuMVdCZ2QKRXJhTVFPNUp4ODBSUkVsb2l0RXRUeGx6YjRNUwotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg=="' ']' + checkTLSSecret some-name-tls-issue-ssl tls.key + local secretName=some-name-tls-issue-ssl + local dataKey=tls.key ++ kubectl_bin get secrets/some-name-tls-issue-ssl -o json ++ jq '.data["tls.key"]' +++ mktemp ++ local LAST_OUT=/tmp/tmp.5OuYi6Uwjd +++ mktemp ++ local LAST_ERR=/tmp/tmp.35MexA4iLq ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl get secrets/some-name-tls-issue-ssl -o json ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.5OuYi6Uwjd ++ cat /tmp/tmp.35MexA4iLq ++ rm /tmp/tmp.5OuYi6Uwjd /tmp/tmp.35MexA4iLq ++ return 0 + local 'secretData="LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb2dJQkFBS0NBUUVBd3FHVXBtZnVwZWNpTDFlSk0wUy96cnZodFR2bFo2bFBYQktVWXBSeVk5enprZHRCCmpkbWRsUmtIdUhUVWVoK1lRV0hqVmI5ODlqTHA5czNrcUlBTFhDWGpFM2lYZ2NUc1hUSTBMNDJRQnNVMTFidEEKWWgrZVVJd0xoUmpmMGttUFYrNjNNMWhSNStTOXhnbDd0bThPRm5xRnNSZitTT3U3VGZuWWxnVk9pb3o5THhmMQpvQi9Lb3FuMnhXMjZNYjA5UTNMNzlwV2twNHpaSjBHU0J3R0JHZ0tDZGtjUUR1MGdpQXdQN0lYamp4bnBsUmJDCmFWS1Jjek14VUM1WXB0SXErM3NUbC9BZUtOQ3hZdDdMZEZGYkN6NXJKS1hzaVN2QysycTNuQjE4MlZ5NTBWYk0KaEFVZ29oK1RpMzljd0E1czBoei82ZHI4WUpaNFVRQk5jbFF3TVFJREFRQUJBb0lCQURaVkV3RXRMRkxGNWlZZgpJcDdjUjBzMzZiZEZKREkrOG5kNmZFL1VydVl2elJMZmlUcEhFSldKcWowVTZDZTdZQzZJWEFVWThwSnIvaUkyCnNlbFQ3VmZvLzYzMDBSNlowWDNtd09peGRRNWV5VHVFRFdJVy80UHV4RnlBYUNMMUEvNEJGc1ZQbDNYTHhpcGQKaFZxVlAvS0llMy9IZWVYellKTlE5dVJTVU8yZUY0TllsUFpGS0pjdDJhS2REc3YvOFZrQnZwd2p0MDlvZmo0cQo2Y05jMjd0U2xHZGx3d2kvRHlaSmViUHBsc2FLenA0am14Vys2VkhLYzdJZDFvU0tCa21GdnNSVnVGL3UxaDN0CnR2aUoxTGlHK2k3NmZzWjJyQlBDeDFZK3BEQktvUkxFUlZYcjlHZ3RUQ1RFYmt4b1JWSHlQd1RjNEtCaWppOGMKRVVtN2N4RUNnWUVBM3NyVWZkOWlGL2NTOHR4bkxKeHlGYjcxd2dwVWx4Z29iRkZFdWRDL0FPTHZteCtqeElLawpBWXhXUk13Y0FkeFlOWUtnMjNhcE9rQ3NZZE1xQlY5enpvMFFpdldyZHI4aURlTEpDYkdVbDJRRk45NHJxU2F4CkhmSjFnZXRMbkhCRjhkemhqbVRXOWE5UmZZQy9IQndBZHE4WWMxMmdxd2hIOEZKa0FUcWk1WlVDZ1lFQTM2UXkKSEw3RUxiZ1VVd0Z1K2UzcUNlL3dkbzVDWUVHaTgwVTNDc0FiNjgzUW40YjNqZVVxek1Vb05xZ1ZxYXM3L0MyaApzbDhtQUowT3hjd2NlMjdnZjFYL2d4UGJEYnZVM2RjS0NFRGJxOE1vVUo1NEt2Q09nY3Q1bjRURlA3c2xWN0xJCjFiUkJydW5odHJHSnlvNmNCV243VjVqZFpla3NNdDNTV01JTFFTMENnWUI3Y2hXRlhUWUVJMkc3Y1lZMWdNWHgKNktwUmh0blNFbytyWE9oZ3NScDBTa29MUU4vRUxjTGtITGRjVFdBalk4ejRjVlhoNUlEbUJ4bTg1bjA5RnVPYgpDaXlsWW5STVNxRjY0ak1ValBIUlpKbERtSFhHdHVxaXRrcUgzekU1RURpaFNBc3VsQTlMZUlZRnJVVzNOSWpKCk9rR3BBckxZc2JEeXB5UkVUaEllZFFLQmdEeXVHb0srS0JDWG43d2Q2WFNhM3lPdkhMbXVROGhHUnVabTQxWmgKWmJJSGVCR3cxejZDN2FmOTNybGx4ZXJ4Y1NjdFluQTViT0JCdlI1aUVXQlVaMGxsbGh5RXFLMERSL0NoUmpHVApGNGQxUGwwUmdsMTBROVpuMVNvNUppUHlyV0VzTzEzd3VObXl6L0Y0SG9EOVRNd1RRNFV6RHU5MTR1NHlUYjZUCmQrWkpBb0dBSDlxSEFRai8rU1ZFK28xT0xBbjRNNDM0dEhXRTFDZ3BDKzB0L2JTSW83L3dEVUlDMmI1d2tKbDYKb0FWUUJsK3NhSnhhZ0xjZ2lZWW9IUmo2TGIrWGV4aW1MbkJHNmJlam1QbDMrcVk0bnFSNG82dGx2dHY5L0xDcwp0ZEUvdHVIeUljMHRMWlAvTk5SU0c0YllTVWxMQndRaVBqSS9mYXJXVzlhZHBMYmpubG89Ci0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0tCg=="' + '[' -z '"LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb2dJQkFBS0NBUUVBd3FHVXBtZnVwZWNpTDFlSk0wUy96cnZodFR2bFo2bFBYQktVWXBSeVk5enprZHRCCmpkbWRsUmtIdUhUVWVoK1lRV0hqVmI5ODlqTHA5czNrcUlBTFhDWGpFM2lYZ2NUc1hUSTBMNDJRQnNVMTFidEEKWWgrZVVJd0xoUmpmMGttUFYrNjNNMWhSNStTOXhnbDd0bThPRm5xRnNSZitTT3U3VGZuWWxnVk9pb3o5THhmMQpvQi9Lb3FuMnhXMjZNYjA5UTNMNzlwV2twNHpaSjBHU0J3R0JHZ0tDZGtjUUR1MGdpQXdQN0lYamp4bnBsUmJDCmFWS1Jjek14VUM1WXB0SXErM3NUbC9BZUtOQ3hZdDdMZEZGYkN6NXJKS1hzaVN2QysycTNuQjE4MlZ5NTBWYk0KaEFVZ29oK1RpMzljd0E1czBoei82ZHI4WUpaNFVRQk5jbFF3TVFJREFRQUJBb0lCQURaVkV3RXRMRkxGNWlZZgpJcDdjUjBzMzZiZEZKREkrOG5kNmZFL1VydVl2elJMZmlUcEhFSldKcWowVTZDZTdZQzZJWEFVWThwSnIvaUkyCnNlbFQ3VmZvLzYzMDBSNlowWDNtd09peGRRNWV5VHVFRFdJVy80UHV4RnlBYUNMMUEvNEJGc1ZQbDNYTHhpcGQKaFZxVlAvS0llMy9IZWVYellKTlE5dVJTVU8yZUY0TllsUFpGS0pjdDJhS2REc3YvOFZrQnZwd2p0MDlvZmo0cQo2Y05jMjd0U2xHZGx3d2kvRHlaSmViUHBsc2FLenA0am14Vys2VkhLYzdJZDFvU0tCa21GdnNSVnVGL3UxaDN0CnR2aUoxTGlHK2k3NmZzWjJyQlBDeDFZK3BEQktvUkxFUlZYcjlHZ3RUQ1RFYmt4b1JWSHlQd1RjNEtCaWppOGMKRVVtN2N4RUNnWUVBM3NyVWZkOWlGL2NTOHR4bkxKeHlGYjcxd2dwVWx4Z29iRkZFdWRDL0FPTHZteCtqeElLawpBWXhXUk13Y0FkeFlOWUtnMjNhcE9rQ3NZZE1xQlY5enpvMFFpdldyZHI4aURlTEpDYkdVbDJRRk45NHJxU2F4CkhmSjFnZXRMbkhCRjhkemhqbVRXOWE5UmZZQy9IQndBZHE4WWMxMmdxd2hIOEZKa0FUcWk1WlVDZ1lFQTM2UXkKSEw3RUxiZ1VVd0Z1K2UzcUNlL3dkbzVDWUVHaTgwVTNDc0FiNjgzUW40YjNqZVVxek1Vb05xZ1ZxYXM3L0MyaApzbDhtQUowT3hjd2NlMjdnZjFYL2d4UGJEYnZVM2RjS0NFRGJxOE1vVUo1NEt2Q09nY3Q1bjRURlA3c2xWN0xJCjFiUkJydW5odHJHSnlvNmNCV243VjVqZFpla3NNdDNTV01JTFFTMENnWUI3Y2hXRlhUWUVJMkc3Y1lZMWdNWHgKNktwUmh0blNFbytyWE9oZ3NScDBTa29MUU4vRUxjTGtITGRjVFdBalk4ejRjVlhoNUlEbUJ4bTg1bjA5RnVPYgpDaXlsWW5STVNxRjY0ak1ValBIUlpKbERtSFhHdHVxaXRrcUgzekU1RURpaFNBc3VsQTlMZUlZRnJVVzNOSWpKCk9rR3BBckxZc2JEeXB5UkVUaEllZFFLQmdEeXVHb0srS0JDWG43d2Q2WFNhM3lPdkhMbXVROGhHUnVabTQxWmgKWmJJSGVCR3cxejZDN2FmOTNybGx4ZXJ4Y1NjdFluQTViT0JCdlI1aUVXQlVaMGxsbGh5RXFLMERSL0NoUmpHVApGNGQxUGwwUmdsMTBROVpuMVNvNUppUHlyV0VzTzEzd3VObXl6L0Y0SG9EOVRNd1RRNFV6RHU5MTR1NHlUYjZUCmQrWkpBb0dBSDlxSEFRai8rU1ZFK28xT0xBbjRNNDM0dEhXRTFDZ3BDKzB0L2JTSW83L3dEVUlDMmI1d2tKbDYKb0FWUUJsK3NhSnhhZ0xjZ2lZWW9IUmo2TGIrWGV4aW1MbkJHNmJlam1QbDMrcVk0bnFSNG82dGx2dHY5L0xDcwp0ZEUvdHVIeUljMHRMWlAvTk5SU0c0YllTVWxMQndRaVBqSS9mYXJXVzlhZHBMYmpubG89Ci0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0tCg=="' ']' + desc 'check if CA issuer created' + set +o xtrace ----------------------------------------------------------------------------------- check if CA issuer created ----------------------------------------------------------------------------------- + compare_kubectl issuer/some-name-tls-issue-pxc-ca-issuer + local resource=issuer/some-name-tls-issue-pxc-ca-issuer + local postfix= + local expected_result=/mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/issuer_some-name-tls-issue-pxc-ca-issuer.yml + local new_result=/tmp/tmp.RPSg5CpXRe/issuer_some-name-tls-issue-pxc-ca-issuer.yml + '[' '!' -z '' -a -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/issuer_some-name-tls-issue-pxc-ca-issuer-oc.yml ']' + '[' 0 = 1 -a -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/issuer_some-name-tls-issue-pxc-ca-issuer-eks.yml ']' + [[ perconalab/percona-xtradb-cluster-operator:main-pxc8.0 =~ 8\.0 ]] + '[' -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/issuer_some-name-tls-issue-pxc-ca-issuer-80.yml ']' + version_gt 1.22 ++ echo '1.20 >= 1.22' ++ bc -l + '[' 0 -eq 1 ']' + return 1 + version_gt 1.21 ++ echo '1.20 >= 1.21' ++ bc -l + '[' 0 -eq 1 ']' + return 1 + kubectl_bin get -o yaml issuer/some-name-tls-issue-pxc-ca-issuer + yq d - '**.uid' + yq d - metadata.resourceVersion + yq d - '**.env.(name==CLUSTER_HASH)' + yq d - metadata.selfLink + yq d - metadata.deletionTimestamp + yq d - 'metadata.annotations."k8s.v1.cni.cncf.io*"' + yq d - 'metadata.annotations."kubernetes.io/psp"' + yq d - '**.clusterIPs' + yq d - '**.procMount' + yq d - '**.storageClassName' + yq d - '**.volumeName' + yq d - '**."percona.com/*"' + yq d - 'metadata.annotations."cloud.google.com/neg"' + yq d - '**.(volumeMode==Filesystem).volumeMode' + yq d - '**."volume.beta.kubernetes.io/storage-provisioner"' + yq d - '**."volume.kubernetes.io/selected-node"' + yq d - '**."volume.kubernetes.io/storage-provisioner"' + yq d - '**.dataSource' + yq d - spec.volumeMode + yq d - '**.creationTimestamp' + yq d - '**.image' + yq d - spec.nodeName + yq d - '**.clusterIP' + yq d - '**."kubernetes.io/pvc-protection"' + yq d - '**.healthCheckNodePort' + yq d - '**.finalizers' + yq d - '**.nodePort' + yq d - '**.enableServiceLinks' + yq d - '**.(name==S3_BUCKET_URL)' + yq d - status + yq d - 'spec.volumeClaimTemplates.*.apiVersion' + yq d - '**.(name==NAMESPACE)' + yq d - '**.imagePullSecrets' + yq d - '**.(name==suffix)' + yq d - '**.(name==S3_BUCKET_PATH)' + yq d - 'spec.volumeClaimTemplates.*.kind' + yq d - 'metadata.ownerReferences.*.apiVersion' + yq d - '**.(name==percona-xtradb-cluster-operator-workload-token*)' + yq d - '**.controller-uid' + yq d - '**.namespace' + yq d - '**.preemptionPolicy' + /usr/bin/sed 's/name: kube-api-access-.*$/name: kube-api-access/' + /usr/bin/sed 's/namespace\:.*name/name/' + /usr/bin/sed s/tls-issue-cert-manager-11948/namespace/g + yq d - spec.ipFamilyPolicy + yq d - spec.ipFamilies + /usr/bin/sed 's#^apiVersion: policy/v1beta1#apiVersion: policy/v1#' + yq d - '**.creationTimestamp' + yq d - metadata.managedFields ++ mktemp + local LAST_OUT=/tmp/tmp.zx88LzwKeS ++ mktemp + local LAST_ERR=/tmp/tmp.Gqtz148e8Z + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl get -o yaml issuer/some-name-tls-issue-pxc-ca-issuer + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.zx88LzwKeS + cat /tmp/tmp.Gqtz148e8Z + rm /tmp/tmp.zx88LzwKeS /tmp/tmp.Gqtz148e8Z + return 0 + diff -u /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/issuer_some-name-tls-issue-pxc-ca-issuer.yml /tmp/tmp.RPSg5CpXRe/issuer_some-name-tls-issue-pxc-ca-issuer.yml + desc 'check if issuer created' + set +o xtrace ----------------------------------------------------------------------------------- check if issuer created ----------------------------------------------------------------------------------- + compare_kubectl issuer/some-name-tls-issue-pxc-issuer + local resource=issuer/some-name-tls-issue-pxc-issuer + local postfix= + local expected_result=/mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/issuer_some-name-tls-issue-pxc-issuer.yml + local new_result=/tmp/tmp.RPSg5CpXRe/issuer_some-name-tls-issue-pxc-issuer.yml + '[' '!' -z '' -a -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/issuer_some-name-tls-issue-pxc-issuer-oc.yml ']' + '[' 0 = 1 -a -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/issuer_some-name-tls-issue-pxc-issuer-eks.yml ']' + [[ perconalab/percona-xtradb-cluster-operator:main-pxc8.0 =~ 8\.0 ]] + '[' -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/issuer_some-name-tls-issue-pxc-issuer-80.yml ']' + version_gt 1.22 ++ echo '1.20 >= 1.22' ++ bc -l + '[' 0 -eq 1 ']' + return 1 + version_gt 1.21 ++ bc -l ++ echo '1.20 >= 1.21' + '[' 0 -eq 1 ']' + return 1 + yq d - '**.finalizers' + yq d - '**.volumeName' + yq d - '**."volume.kubernetes.io/storage-provisioner"' + yq d - spec.volumeMode + yq d - metadata.deletionTimestamp + yq d - '**."volume.beta.kubernetes.io/storage-provisioner"' + yq d - 'metadata.annotations."k8s.v1.cni.cncf.io*"' + yq d - '**.dataSource' + yq d - 'metadata.annotations."kubernetes.io/psp"' + yq d - 'metadata.annotations."cloud.google.com/neg"' + yq d - metadata.resourceVersion + yq d - '**.(name==percona-xtradb-cluster-operator-workload-token*)' + yq d - '**.env.(name==CLUSTER_HASH)' + yq d - '**.creationTimestamp' + yq d - metadata.selfLink + yq d - '**.image' + yq d - '**.clusterIPs' + yq d - '**.clusterIP' + yq d - '**.(volumeMode==Filesystem).volumeMode' + yq d - '**.storageClassName' + yq d - '**.healthCheckNodePort' + yq d - '**."kubernetes.io/pvc-protection"' + yq d - '**.nodePort' + yq d - '**.procMount' + yq d - '**.namespace' + yq d - '**.imagePullSecrets' + yq d - spec.nodeName + yq d - '**.enableServiceLinks' + yq d - '**."volume.kubernetes.io/selected-node"' + yq d - '**.creationTimestamp' + yq d - '**.uid' + yq d - '**."percona.com/*"' + yq d - metadata.managedFields + kubectl_bin get -o yaml issuer/some-name-tls-issue-pxc-issuer + yq d - 'spec.volumeClaimTemplates.*.apiVersion' + yq d - status + yq d - 'spec.volumeClaimTemplates.*.kind' + yq d - '**.(name==S3_BUCKET_PATH)' + yq d - 'metadata.ownerReferences.*.apiVersion' + yq d - '**.(name==suffix)' ++ mktemp + yq d - '**.(name==NAMESPACE)' + yq d - spec.ipFamilyPolicy + /usr/bin/sed 's#^apiVersion: policy/v1beta1#apiVersion: policy/v1#' + /usr/bin/sed 's/name: kube-api-access-.*$/name: kube-api-access/' + /usr/bin/sed 's/namespace\:.*name/name/' + local LAST_OUT=/tmp/tmp.h5chWtUOd5 + yq d - '**.controller-uid' + /usr/bin/sed s/tls-issue-cert-manager-11948/namespace/g + yq d - '**.(name==S3_BUCKET_URL)' + yq d - '**.preemptionPolicy' + yq d - spec.ipFamilies ++ mktemp + local LAST_ERR=/tmp/tmp.OwT26jXnXG + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl get -o yaml issuer/some-name-tls-issue-pxc-issuer + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.h5chWtUOd5 + cat /tmp/tmp.OwT26jXnXG + rm /tmp/tmp.h5chWtUOd5 /tmp/tmp.OwT26jXnXG + return 0 + diff -u /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/issuer_some-name-tls-issue-pxc-issuer.yml /tmp/tmp.RPSg5CpXRe/issuer_some-name-tls-issue-pxc-issuer.yml + desc 'check if certificate issued' + set +o xtrace ----------------------------------------------------------------------------------- check if certificate issued ----------------------------------------------------------------------------------- + compare_kubectl certificate/some-name-tls-issue-ssl + local resource=certificate/some-name-tls-issue-ssl + local postfix= + local expected_result=/mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/certificate_some-name-tls-issue-ssl.yml + local new_result=/tmp/tmp.RPSg5CpXRe/certificate_some-name-tls-issue-ssl.yml + '[' '!' -z '' -a -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/certificate_some-name-tls-issue-ssl-oc.yml ']' + '[' 0 = 1 -a -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/certificate_some-name-tls-issue-ssl-eks.yml ']' + [[ perconalab/percona-xtradb-cluster-operator:main-pxc8.0 =~ 8\.0 ]] + '[' -f /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/certificate_some-name-tls-issue-ssl-80.yml ']' + version_gt 1.22 ++ echo '1.20 >= 1.22' ++ bc -l + '[' 0 -eq 1 ']' + return 1 + version_gt 1.21 ++ echo '1.20 >= 1.21' ++ bc -l + '[' 0 -eq 1 ']' + return 1 + kubectl_bin get -o yaml certificate/some-name-tls-issue-ssl + yq d - '**.namespace' + yq d - '**.uid' + yq d - metadata.resourceVersion + yq d - '**.env.(name==CLUSTER_HASH)' + yq d - metadata.selfLink + yq d - metadata.deletionTimestamp + yq d - 'metadata.annotations."k8s.v1.cni.cncf.io*"' + yq d - '**.clusterIPs' + yq d - '**.dataSource' + yq d - '**.volumeName' + yq d - '**."percona.com/*"' + yq d - '**.procMount' + yq d - '**."volume.beta.kubernetes.io/storage-provisioner"' + yq d - '**."volume.kubernetes.io/storage-provisioner"' + yq d - '**.storageClassName' + yq d - spec.volumeMode + yq d - '**.(name==percona-xtradb-cluster-operator-workload-token*)' + yq d - spec.nodeName + yq d - '**.creationTimestamp' + yq d - '**."volume.kubernetes.io/selected-node"' + yq d - '**.image' + yq d - '**.clusterIP' + yq d - '**.finalizers' + yq d - '**.nodePort' + yq d - '**."kubernetes.io/pvc-protection"' + yq d - '**.(volumeMode==Filesystem).volumeMode' + yq d - '**.imagePullSecrets' + yq d - '**.healthCheckNodePort' + yq d - '**.(name==NAMESPACE)' + yq d - '**.enableServiceLinks' + yq d - status + yq d - 'metadata.annotations."cloud.google.com/neg"' + yq d - 'metadata.annotations."kubernetes.io/psp"' + yq d - '**.(name==suffix)' + yq d - spec.ipFamilies + yq d - 'spec.volumeClaimTemplates.*.kind' + yq d - 'metadata.ownerReferences.*.apiVersion' + yq d - '**.controller-uid' + yq d - '**.(name==S3_BUCKET_PATH)' + yq d - 'spec.volumeClaimTemplates.*.apiVersion' + yq d - '**.(name==S3_BUCKET_URL)' + yq d - '**.preemptionPolicy' + yq d - spec.ipFamilyPolicy + /usr/bin/sed 's#^apiVersion: policy/v1beta1#apiVersion: policy/v1#' + /usr/bin/sed 's/name: kube-api-access-.*$/name: kube-api-access/' + yq d - '**.creationTimestamp' + /usr/bin/sed 's/namespace\:.*name/name/' + /usr/bin/sed s/tls-issue-cert-manager-11948/namespace/g + yq d - metadata.managedFields ++ mktemp + local LAST_OUT=/tmp/tmp.0EFDqQKSwZ ++ mktemp + local LAST_ERR=/tmp/tmp.w2oeZJHl0Z + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl get -o yaml certificate/some-name-tls-issue-ssl + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.0EFDqQKSwZ + cat /tmp/tmp.w2oeZJHl0Z + rm /tmp/tmp.0EFDqQKSwZ /tmp/tmp.w2oeZJHl0Z + return 0 + diff -u /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/compare/certificate_some-name-tls-issue-ssl.yml /tmp/tmp.RPSg5CpXRe/certificate_some-name-tls-issue-ssl.yml + apply_config /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/some-name-tls-issue-haproxy.yml + '[' -z '' ']' + cat_config /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/some-name-tls-issue-haproxy.yml + kubectl_bin apply -f - ++ mktemp + cat /mnt/jenkins/workspace/cloud-pxc-operator_PR-1125/e2e-tests/tls-issue-cert-manager/conf/some-name-tls-issue-haproxy.yml + /usr/bin/sed -e 's#apiVersion: pxc.percona.com/v.*$#apiVersion: pxc.percona.com/v1-11-0#' + local LAST_OUT=/tmp/tmp.6yBAWJvIeW + /usr/bin/sed -e 's#image:.*-pmm$#image: perconalab/pmm-client:dev-latest#' + /usr/bin/sed -e 's#image:.*-backup$#image: perconalab/percona-xtradb-cluster-operator:main-pxc8.0-backup#' + /usr/bin/sed -e 's#initImage:.*-init$#initImage: perconalab/percona-xtradb-cluster-operator:PR-1125-706f792a#' ++ mktemp + /usr/bin/sed -e 's#image:.*\/percona-xtradb-cluster:.*$#image: perconalab/percona-xtradb-cluster-operator:main-pxc8.0#' + /usr/bin/sed -e 's#image:.*-pxc\([0-9]*.[0-9]*\)\{0,1\}$#image: perconalab/percona-xtradb-cluster-operator:main-pxc8.0#' + /usr/bin/sed -e 's#image:.*-proxysql$#image: perconalab/percona-xtradb-cluster-operator:main-proxysql#' + /usr/bin/sed -e 's#image:.*-logcollector$#image: perconalab/percona-xtradb-cluster-operator:main-logcollector#' + /usr/bin/sed -e s~minio-service.#namespace~minio-service.tls-issue-cert-manager-11948~ + /usr/bin/sed -e 's#image:.*-haproxy$#image: perconalab/percona-xtradb-cluster-operator:main-haproxy#' + /usr/bin/sed -e 's#apply:.*#apply: Never#' + local LAST_ERR=/tmp/tmp.On376MaEq1 + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl apply -f - + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.6yBAWJvIeW perconaxtradbcluster.pxc.percona.com/some-name-tls-issue configured + cat /tmp/tmp.On376MaEq1 + rm /tmp/tmp.6yBAWJvIeW /tmp/tmp.On376MaEq1 + return 0 + wait_for_running some-name-tls-issue-haproxy 1 + local name=some-name-tls-issue-haproxy + let last_pod=0 + : + local max_retry=480 ++ seq 0 0 + for i in '$(seq 0 $last_pod)' + wait_pod some-name-tls-issue-haproxy-0 480 + local pod=some-name-tls-issue-haproxy-0 + local max_retry=480 + local ns= ++ echo some-name-tls-issue-haproxy-0 ++ /usr/bin/sed -E 's/.*-(pxc|proxysql)-[0-9]/\1/' ++ egrep '^(pxc|proxysql)$' + local container= + set +o xtrace some-name-tls-issue-haproxy-0...........error: a container name must be specified for pod some-name-tls-issue-haproxy-0, choose one of: [haproxy pxc-monit] .Ok + desc 'check ssl-internal certificate using PXC' + set +o xtrace ----------------------------------------------------------------------------------- check ssl-internal certificate using PXC ----------------------------------------------------------------------------------- + check_verify_identity some-name-tls-issue-pxc + local host=some-name-tls-issue-pxc + local command=exit + local 'args=--ssl-ca=/etc/mysql/ssl-internal/ca.crt --ssl-mode=VERIFY_IDENTITY --protocol=tcp -uroot -proot_password --host=some-name-tls-issue-pxc' + kubectl_bin exec some-name-tls-issue-pxc-0 -- bash -c 'printf '\''%s\n'\'' "exit" | mysql -sN --ssl-ca=/etc/mysql/ssl-internal/ca.crt --ssl-mode=VERIFY_IDENTITY --protocol=tcp -uroot -proot_password --host=some-name-tls-issue-pxc' ++ mktemp + local LAST_OUT=/tmp/tmp.w4lFmCVmHA ++ mktemp + local LAST_ERR=/tmp/tmp.m5sRVj8zkN + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl exec some-name-tls-issue-pxc-0 -- bash -c 'printf '\''%s\n'\'' "exit" | mysql -sN --ssl-ca=/etc/mysql/ssl-internal/ca.crt --ssl-mode=VERIFY_IDENTITY --protocol=tcp -uroot -proot_password --host=some-name-tls-issue-pxc' + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.w4lFmCVmHA + cat /tmp/tmp.m5sRVj8zkN mysql: [Warning] Using a password on the command line interface can be insecure. + rm /tmp/tmp.w4lFmCVmHA /tmp/tmp.m5sRVj8zkN + return 0 + desc 'check ssl-internal certificate using HAProxy' + set +o xtrace ----------------------------------------------------------------------------------- check ssl-internal certificate using HAProxy ----------------------------------------------------------------------------------- + check_verify_identity some-name-tls-issue-haproxy + local host=some-name-tls-issue-haproxy + local command=exit + local 'args=--ssl-ca=/etc/mysql/ssl-internal/ca.crt --ssl-mode=VERIFY_IDENTITY --protocol=tcp -uroot -proot_password --host=some-name-tls-issue-haproxy' + kubectl_bin exec some-name-tls-issue-pxc-0 -- bash -c 'printf '\''%s\n'\'' "exit" | mysql -sN --ssl-ca=/etc/mysql/ssl-internal/ca.crt --ssl-mode=VERIFY_IDENTITY --protocol=tcp -uroot -proot_password --host=some-name-tls-issue-haproxy' ++ mktemp + local LAST_OUT=/tmp/tmp.VQntX40W8A ++ mktemp + local LAST_ERR=/tmp/tmp.Pa9T63aU49 + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl exec some-name-tls-issue-pxc-0 -- bash -c 'printf '\''%s\n'\'' "exit" | mysql -sN --ssl-ca=/etc/mysql/ssl-internal/ca.crt --ssl-mode=VERIFY_IDENTITY --protocol=tcp -uroot -proot_password --host=some-name-tls-issue-haproxy' + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.VQntX40W8A + cat /tmp/tmp.Pa9T63aU49 mysql: [Warning] Using a password on the command line interface can be insecure. + rm /tmp/tmp.VQntX40W8A /tmp/tmp.Pa9T63aU49 + return 0 + destroy tls-issue-cert-manager-11948 + local namespace=tls-issue-cert-manager-11948 + local ignore_logs=false + [[ false == \f\a\l\s\e ]] + grep -v 'get backup status: Job.batch' + grep -v 'the object has been modified' + /usr/bin/sed -r 's/"ts":[0-9.]+//; s^limits-[0-9.]+/^^g' + sort -u + tee /tmp/tmp.RPSg5CpXRe/operator.log + grep -v level=info ++ get_operator_pod ++ local label_prefix=app.kubernetes.io/ +++ kubectl get pods --selector=app.kubernetes.io/name=percona-xtradb-cluster-operator -n pxc-operator +++ grep -c percona-xtradb-cluster-operator ++ local check_label=1 ++ [[ 1 -eq 0 ]] ++ kubectl_bin get pods --selector=app.kubernetes.io/name=percona-xtradb-cluster-operator -o 'jsonpath={.items[].metadata.name}' -n pxc-operator +++ mktemp ++ local LAST_OUT=/tmp/tmp.6Etg5bwqWs +++ mktemp ++ local LAST_ERR=/tmp/tmp.kHYimYsYc7 ++ local exit_status=0 +++ seq 0 2 ++ for i in '$(seq 0 2)' ++ kubectl get pods --selector=app.kubernetes.io/name=percona-xtradb-cluster-operator -o 'jsonpath={.items[].metadata.name}' -n pxc-operator ++ exit_status=0 ++ [[ 0 != 0 ]] ++ break ++ cat /tmp/tmp.6Etg5bwqWs ++ cat /tmp/tmp.kHYimYsYc7 ++ rm /tmp/tmp.6Etg5bwqWs /tmp/tmp.kHYimYsYc7 ++ return 0 + kubectl_bin logs -n pxc-operator percona-xtradb-cluster-operator-5699d7755d-xqvwd ++ mktemp + local LAST_OUT=/tmp/tmp.x9GsNLAajD ++ mktemp + local LAST_ERR=/tmp/tmp.WtOGOKnsQh + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl logs -n pxc-operator percona-xtradb-cluster-operator-5699d7755d-xqvwd + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.x9GsNLAajD + cat /tmp/tmp.WtOGOKnsQh + rm /tmp/tmp.x9GsNLAajD /tmp/tmp.WtOGOKnsQh + return 0 I0412 13:28:49.718635 1 request.go:645] Throttling request took 1.045695907s, request: GET:https://10.7.240.1:443/apis/pxc.percona.com/v1-1-0?timeout=32s I0412 13:30:39.320971 1 request.go:645] Throttling request took 1.045153898s, request: GET:https://10.7.240.1:443/apis/migration.k8s.io/v1alpha1?timeout=32s {"level":"info",,"caller":"pxc/controller.go:468","msg":"reconcile replication error","err":"get primary pxc pod: failed to get proxySQL db: dial tcp 10.7.254.134:3306: connect: connection refused"} {"level":"info",,"caller":"pxc/controller.go:468","msg":"reconcile replication error","err":"get primary pxc pod: not found"} {"level":"info",,"caller":"pxc/version.go:328","msg":"update PXC version (fetched from db)","new version":"8.0.27-18.1"} {"level":"info",,"caller":"v1/pxc_types.go:874","msg":"HAProxy size will be changed from 1 to 2 due to safe config"} {"level":"info",,"caller":"v1/pxc_types.go:874","msg":"ProxySQL size will be changed from 1 to 2 due to safe config"} {"level":"info",,"caller":"v1/pxc_types.go:875","msg":"Set allowUnsafeConfigurations=true to disable safe configuration"} {"level":"info",,"logger":"cmd","msg":"Git commit: 706f792ae47c369cb3556faff186b6873a8a247f Git branch: PR-1125-706f792a Build time: 2022-04-12T09:09:41Z"} {"level":"info",,"logger":"cmd","msg":"Go OS/Arch: linux/amd64"} {"level":"info",,"logger":"cmd","msg":"Go Version: go1.17.8"} {"level":"info",,"logger":"cmd","msg":"operator-sdk Version: v0.19.4"} {"level":"info",,"logger":"cmd","msg":"Registering Components."} {"level":"info",,"logger":"cmd","msg":"Runs on","platform":"kubernetes","version":"v1.20.15-gke.4100"} {"level":"info",,"logger":"cmd","msg":"Starting the Cmd."} {"level":"info",,"logger":"controller-runtime.certwatcher","msg":"Starting certificate watcher"} {"level":"info",,"logger":"controller-runtime.certwatcher","msg":"Updated current TLS certificate"} {"level":"info",,"logger":"controller-runtime.manager.controller.perconaxtradbclusterbackup-controller","msg":"Starting Controller"} {"level":"info",,"logger":"controller-runtime.manager.controller.perconaxtradbclusterbackup-controller","msg":"Starting EventSource","source":"kind source: /, Kind="} {"level":"info",,"logger":"controller-runtime.manager.controller.perconaxtradbclusterbackup-controller","msg":"Starting workers","worker count":1} {"level":"info",,"logger":"controller-runtime.manager.controller.perconaxtradbcluster-controller","msg":"Starting Controller"} {"level":"info",,"logger":"controller-runtime.manager.controller.perconaxtradbcluster-controller","msg":"Starting EventSource","source":"kind source: /, Kind="} {"level":"info",,"logger":"controller-runtime.manager.controller.perconaxtradbcluster-controller","msg":"Starting workers","worker count":1} {"level":"info",,"logger":"controller-runtime.manager.controller.perconaxtradbclusterrestore-controller","msg":"Starting Controller"} {"level":"info",,"logger":"controller-runtime.manager.controller.perconaxtradbclusterrestore-controller","msg":"Starting EventSource","source":"kind source: /, Kind="} {"level":"info",,"logger":"controller-runtime.manager.controller.perconaxtradbclusterrestore-controller","msg":"Starting workers","worker count":1} {"level":"info",,"logger":"controller-runtime.manager","msg":"starting metrics server","path":"/metrics"} {"level":"info",,"logger":"controller-runtime.metrics","msg":"metrics server is starting to listen","addr":":8080"} {"level":"info",,"logger":"controller-runtime.webhook","msg":"registering webhook","path":"/validate-percona-xtradbcluster"} {"level":"info",,"logger":"controller-runtime.webhook","msg":"serving webhook server","host":"","port":9443} {"level":"info",,"logger":"controller-runtime.webhook.webhooks","msg":"starting webhook server"} {"level":"info",,"logger":"leader","msg":"Became the leader."} {"level":"info",,"logger":"leader","msg":"No pre-existing lock was found."} {"level":"info",,"logger":"leader","msg":"Trying to become the leader."} + grep -v NAMESPACE + kubectl get pxc --all-namespaces -o wide + xargs -L 1 sh -xc 'kubectl patch pxc -n $0 $1 --type=merge -p "{\"metadata\":{\"finalizers\":[]}}"' + kubectl patch pxc -n tls-issue-cert-manager-11948 some-name-tls-issue --type=merge -p '{"metadata":{"finalizers":[]}}' perconaxtradbcluster.pxc.percona.com/some-name-tls-issue patched + kubectl_bin delete pxc --all --all-namespaces ++ mktemp + local LAST_OUT=/tmp/tmp.KwCaor6KkN ++ mktemp + local LAST_ERR=/tmp/tmp.8NOWUr760X + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl delete pxc --all --all-namespaces + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.KwCaor6KkN perconaxtradbcluster.pxc.percona.com "some-name-tls-issue" deleted + cat /tmp/tmp.8NOWUr760X + rm /tmp/tmp.KwCaor6KkN /tmp/tmp.8NOWUr760X + return 0 + kubectl_bin delete pxc-backup --all --all-namespaces ++ mktemp + local LAST_OUT=/tmp/tmp.i5D0IlMmcy ++ mktemp + local LAST_ERR=/tmp/tmp.JVPh984L9n + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl delete pxc-backup --all --all-namespaces + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.i5D0IlMmcy No resources found + cat /tmp/tmp.JVPh984L9n + rm /tmp/tmp.i5D0IlMmcy /tmp/tmp.JVPh984L9n + return 0 + kubectl_bin delete pxc-restore --all --all-namespaces ++ mktemp + local LAST_OUT=/tmp/tmp.CtmL7KfdSh ++ mktemp + local LAST_ERR=/tmp/tmp.WQKKfRmoP1 + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl delete pxc-restore --all --all-namespaces + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.CtmL7KfdSh No resources found + cat /tmp/tmp.WQKKfRmoP1 + rm /tmp/tmp.CtmL7KfdSh /tmp/tmp.WQKKfRmoP1 + return 0 + kubectl_bin delete ValidatingWebhookConfiguration percona-xtradbcluster-webhook ++ mktemp + local LAST_OUT=/tmp/tmp.VQV6RQ6WBg ++ mktemp + local LAST_ERR=/tmp/tmp.P34OGQmpqU + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl delete ValidatingWebhookConfiguration percona-xtradbcluster-webhook + exit_status=0 + [[ 0 != 0 ]] + break + cat /tmp/tmp.VQV6RQ6WBg validatingwebhookconfiguration.admissionregistration.k8s.io "percona-xtradbcluster-webhook" deleted + cat /tmp/tmp.P34OGQmpqU + rm /tmp/tmp.VQV6RQ6WBg /tmp/tmp.P34OGQmpqU + return 0 + kubectl_bin delete -f https://github.com/jetstack/cert-manager/releases/download/v1.5.4/cert-manager.yaml namespace "cert-manager" deleted + : + '[' '!' -z '' ']' + '[' -n pxc-operator ']' + kubectl_bin delete --grace-period=0 --force=true namespace tls-issue-cert-manager-11948 + rm -rf /tmp/tmp.RPSg5CpXRe ++ mktemp + kubectl_bin delete --grace-period=0 --force=true namespace pxc-operator ++ mktemp + local LAST_OUT=/tmp/tmp.4ufqtO1hHu ++ mktemp + local LAST_OUT=/tmp/tmp.4PzSlyBJGp + local LAST_ERR=/tmp/tmp.7aA1DCrsvz + local exit_status=0 ++ mktemp ++ seq 0 2 + local LAST_ERR=/tmp/tmp.f8dYz8MMes + local exit_status=0 ++ seq 0 2 + for i in '$(seq 0 2)' + kubectl delete --grace-period=0 --force=true namespace pxc-operator + for i in '$(seq 0 2)' + kubectl delete --grace-period=0 --force=true namespace tls-issue-cert-manager-11948