apupier opened a new pull request, #27509: URL: https://github.com/apache/camel/pull/27509
Two bugs caused all SpiffeWorkloadApiIT and SpiffeMutualTlsIT tests to fail with PERMISSION_DENIED: no identity issued on rootless container (by default for podman and by default on Jenkins CI) **Wrong workload UID under rootless Podman** createWorkloadEntry() registered the SPIRE unix:uid selector using UnixSystem.getUid(), which returns the host UID of the test process (e.g. 1000). Under rootless Podman every container runs in a Linux user namespace where the owner's host UID is mapped to UID 0 inside the container. The agent uses that user namespace when reading /proc/<pid>/status to attest workloads, so it sees the test process as UID 0 - not 1000. The mismatch meant no workload entry ever matched, producing PERMISSION_DENIED for every SVID request. Fix: add resolveWorkloadUid() which calls DockerClientFactory's info API and checks the "Rootless" key in the raw JSON response (Podman sets it to true; the docker-java Info model has no typed field for it, so it lands in rawValues). When rootless, return 0; otherwise fall back to the real host UID from UnixSystem. **No agent readiness gate after socket creation** waitForSocket() only checked that the socket file existed, returning the moment the file appeared. At that point the agent had just created the socket but had not finished its initial sync with the SPIRE server and was not yet ready to serve workload requests. Fix: add waitForAgentHealthy() which polls "spire-agent healthcheck -socketPath ..." inside the running agent container, mirroring the existing waitForServerHealthy() pattern for the server. initialize() now calls waitForSocket() followed by waitForAgentHealthy() before handing the service to the tests. Co-authored-by: IBM Bob 2.2.1 # Description <!-- - Write a pull request description that is detailed enough to understand what the pull request does, how, and why. --> # Target - [ ] I checked that the commit is targeting the correct branch (Camel 4 uses the `main` branch) # Tracking - [ ] If this is a large change, bug fix, or code improvement, I checked there is a [JIRA issue](https://issues.apache.org/jira/browse/CAMEL) filed for the change (usually before you start working on it). <!-- # *Note*: trivial changes like, typos, minor documentation fixes and other small items do not require a JIRA issue. In this case your pull request should address just this issue, without pulling in other changes. --> # Apache Camel coding standards and style - [ ] I checked that each commit in the pull request has a meaningful subject line and body. <!-- If you're unsure, you can format the pull request title like `[CAMEL-XXX] Fixes bug in camel-file component`, where you replace `CAMEL-XXX` with the appropriate JIRA issue. --> - [ ] I have run `mvn clean install -DskipTests` locally from root folder and I have committed all auto-generated changes. <!-- You can run the aforementioned command in your module so that the build auto-formats your code. This will also be verified as part of the checks and your PR may be rejected if if there are uncommited changes after running `mvn clean install -DskipTests`. You can learn more about the contribution guidelines at https://github.com/apache/camel/blob/main/CONTRIBUTING.md --> # AI-assisted contributions - [ ] If this PR includes AI-generated code, commits have proper co-authorship attribution (e.g., `Co-authored-by` trailers) and the PR description identifies the AI tool used. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
