E2E Tests: Intermittent TestTerraformModuleTest failures due to stale RBAC permissions from previous test
@maniSbindra がすでに取り組んでいます。
2026年2月26日 から。
評価
この issue はまだ評価されていません。
説明
Summary
The daily scheduled E2E pipeline (🧪 E2E Tests) has a ~27% failure rate (8 failures in the last 30 runs). The most frequent flaky test is TestTerraformModuleTest, which intermittently finds 5 permissions instead of the expected 8.
Root Cause
The tests share a single service principal per (os, type) matrix combination. Each test calls DetachRolesFromSP at startup to remove all role assignments, then waits 15 seconds for Azure RBAC de-propagation before creating a new custom role and starting the MPF iteration loop.
However, 15 seconds is often insufficient for Azure to fully de-propagate the previous test's role assignments. When TestTerraformModuleTest starts after TestTerraformACINoTfvarsFile (which discovers resourcegroups/{read,write,delete}), the SP may still effectively have those permissions cached from the prior test's custom role.
What happens on a failed run
Traced from runs #21550858823 (Jan 31) and #21840777556 (Feb 9):
| Iteration | What happened | Permission discovered |
|---|---|---|
| 0 | azurerm_resource_group.this: Creation complete after 13s — RG created successfully, then workspaces/read denied |
workspaces/read |
| 1 | RG refreshed OK, workspaces/write denied |
workspaces/write |
| 2 | Deployment succeeds → enters destroy phase → "Authorization Successful" | workspaces/delete (from destroy) |
Result: 5 permissions found (workspaces/{read,write,delete} + deployments/{read,write} from initial)
Expected: 8 permissions (the above + resourcegroups/{read,write,delete})
The 3 missing resourcegroups/* permissions were never surfaced as AuthorizationFailed errors because the SP still had them from the previous test's role assignment that hadn't fully de-propagated.
Key evidence
- The resource group is created by Terraform (not by MPF —
autoCreateResourceGroupisfalsefor all Terraform tests) - The RG creation succeeds without any auth error in iteration 0, proving the SP still has
resourcegroups/writefrom the prior test - The same 3 permissions are missing in every occurrence (Jan 31 and Feb 9 show identical patterns)
- The test runs sequentially (
-p 1 -parallel 1), so the issue is temporal, not concurrent
Affected Code
pkg/usecase/mpfService.goline 112:time.Sleep(15 * time.Second)— wait after role deletione2eTests/e2eTerraform_test.go:229:assert.Equal(t, 8, len(perms))— exact count assertion
Failed Runs
| Date | Run ID | Test | Error |
|---|---|---|---|
| Feb 24 | 22370086522 | TestARMTemplatMultiResourceTemplateFullDeployment |
54 perms, expected ≥57 (same root cause) |
| Feb 9 | 21840777556 | TestTerraformModuleTest |
5 perms, expected 8 |
| Jan 31 | 21550858823 | TestTerraformModuleTest |
5 perms, expected 8 |
Proposed Solutions
- Short-term: Increase the RBAC de-propagation wait from 15s to 45s
- Medium-term: Replace the fixed sleep with an active probe — poll until a test API call returns
403 AuthorizationFailed, confirming old permissions are fully revoked - Long-term: Use separate service principals per test function to eliminate cross-test RBAC contamination entirely
- 主要言語
- Go
- スター
- 66
- フォーク
- 11
- 平均マージ
- 2時間 7分
- マージ済み PR(30日)
- 5
環境構築
このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドなし
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
Azure/mpf のほかの issue
-
bug
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
-
CreateUpdateCustomRole returns nil after exhausting its retry budget, reporting success when the role was never updated対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープンbug
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
-
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
-
Add optional flag which does not destroy the resources created including the custom role definition再び着手できるかも このイシューのプルリクエストはマージされずにクローズされました。 オープンenhancement terraform
-
For Terraform azurerm provider resources which use LRO polling add RESOURCE_TYPE/operationStatuses/read permissions対応中かも @bgdnext64 が 73 日前に担当しました。 オープンenhancement terraform
似ている issue
-
enhancement exporter/awss3 needs triage
難易度 2/5 1〜3時間 初心者へのやさしさ 66/100
open-telemetry/opentelemetry-collector-contrib#51905 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
area/docs theme/validation
難易度 1/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
a11y P1-significant
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
[correctness][missing-coverage][sort] Strict uniqueness checks lack numeric-key equivalence coverageオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 77/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 83/100
infiniflow/ragflow#20625 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信