Skip to content

CI: Conformance AKS (ci-aks) - secrets not found #37874

@marseel

Description

@marseel

CI failure

Example failures https://github.com/cilium/cilium/actions/runs/13488176179/job/37682127143

Found 1 logs in cilium-cilium-13488176179-1-1/kube-system/cilium-7qk5b (cilium-agent) matching list of errors that must be investigated:
time="2025-02-24T00:25:09.651206259Z" level=warning msg="Failed fetching K8s Secret, header match will fail" error="secrets \"header-match\" not found" subsys=envoy-manager (1 occurrences)

Example run https://github.com/cilium/cilium/actions/runs/13510490387/job/37749578473

Found 16 logs in cilium-cilium-13510490387-1-1/kube-system/cilium-wnfsq (cilium-agent) matching list of errors that must be investigated:
time="2025-02-25T00:40:08.007407422Z" level=error msg="endpoint regeneration failed" ciliumEndpointName=cilium-test-5/client-59476dbc54-bg5jw containerID=f374598e47 containerInterface= datapathPolicyRevision=169 desiredPolicyRevision=165 endpointID=534 error="unable to regenerate policy for '534': secrets \"externaltarget-tls\" not found" identity=15503 ipv4=192.168.1.161 ipv6="fd00::1f9" k8sPodName=cilium-test-5/client-59476dbc54-bg5jw subsys=endpoint (1 occurrences)
time="2025-02-25T00:40:08.015650889Z" level=warning msg="Failed to calculate SelectorPolicy" ciliumEndpointName=cilium-test-5/client2-6b89df6c77-6pzsj containerID=b35bb5a633 containerInterface= datapathPolicyRevision=169 desiredPolicyRevision=165 endpointID=346 error="secrets \"externaltarget-tls\" not found" identity=53608 ipv4=192.168.1.58 ipv6="fd00::10f" k8sPodName=cilium-test-5/client2-6b89df6c77-6pzsj subsys=endpoint (1 occurrences)

First occurrence I was able to find is from ~3 days ago: https://github.com/cilium/cilium/actions/runs/13477728748/job/37658955453
Since then, this error happens quite often, around ~50% failure rate on main branch: https://github.com/cilium/cilium/actions/workflows/conformance-aks.yaml?query=branch%3Amain

Metadata

Metadata

Assignees

Labels

area/CIContinuous Integration testing issue or flakearea/servicemeshGH issues or PRs regarding servicemeshci/flakeThis is a known failure that occurs in the tree. Please investigate me!

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions