test(crd-e2e): make the deferred-dimension log check rotation-proof - #12
Merged
Merged
Conversation
Test 15's "agent logged the deferred dimensions" check was flaky in CI (green on the arm64 box, red on the amd64 GitHub runner). The old check hoped a past "not enforceable" line was still readable via `kubectl logs --since`, but the JSON-output agent streams every node egress event and containerd rotates the container log — `kubectl logs` reads only the current segment, so the periodic deferred-dimension line can rotate out from under it. Force a fresh emission instead: bump an annotation on the deferred-dims policy (→ informer update → Programmer apply() → the deferred-dimension log fires now), then grep a short, just-written window on the named agent pod. Retried across ten applies, so log rotation and re-walk cadence can't hide it. The decisive "port-only deny did NOT drop" assertion is unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Test 15's "agent logged the deferred dimensions" check was flaky in CI (green on the arm64 box, red on the amd64 GitHub runner). The old check hoped a past "not enforceable" line was still readable via
kubectl logs --since, but the JSON-output agent streams every node egress event and containerd rotates the container log —kubectl logsreads only the current segment, so the periodic deferred-dimension line can rotate out from under it.Force a fresh emission instead: bump an annotation on the deferred-dims policy (→ informer update → Programmer apply() → the deferred-dimension log fires now), then grep a short, just-written window on the named agent pod. Retried across ten applies, so log rotation and re-walk cadence can't hide it. The decisive "port-only deny did NOT drop" assertion is unchanged.