testcontainers / testcontainers/testcontainers-java

[Bug]: Giving SSLHandshakeException while executing PATCH command

Open
#9,197 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

type/bug
Dominant language
Java
Stars
8.7k
Forks
1.9k
Avg merge
2d 17h
Merged PRs (30d)
9

Description

Module

K3S

Testcontainers version

1.20.1

Using the latest Testcontainers version?

Yes

Host OS

Windows

Host Arch

x86

Docker version
Client:
 Cloud integration: v1.0.29
 Version:           20.10.20
 API version:       1.41
 Go version:        go1.18.7
 Git commit:        9fdeb9c
 Built:             Tue Oct 18 18:28:44 2022
 OS/Arch:           windows/amd64
 Context:           default
 Experimental:      true

Server: Docker Desktop 4.13.1 (90346)
 Engine:
  Version:          20.10.20
  API version:      1.41 (minimum version 1.12)
  Go version:       go1.18.7
  Git commit:       03df974
  Built:            Tue Oct 18 18:18:35 2022
  OS/Arch:          linux/amd64
  Experimental:     false
 containerd:
  Version:          1.6.8
  GitCommit:        9cd3357b7fd7218e4aec3eae239db1f68a5a6ec6
 runc:
  Version:          1.1.4
  GitCommit:        v1.1.4-0-g5fd4c4d
 docker-init:
  Version:          0.19.0
  GitCommit:        de40ad0
What happened?

My K3S test container is up and I am able to create namespace, services etc. in it.

            V1Service service = new V1Service()
            .metadata(new V1ObjectMeta().name(serviceName).annotations(annotations))
            .spec(new V1ServiceSpec()
                    .addPortsItem(new V1ServicePort()
                            .port(80)
                            .targetPort(new IntOrString(8080)))
                    .selector(Collections.singletonMap("app", "my-app"))
                    .type("ClusterIP"));

    api.createNamespacedService(LHTestConstants.NAMESPACE, service).execute();

But when I try to run a PATCH command using the below code it gives a SSLHandshake error:

           V1Patch patch = new V1Patch(patchJson);
           V1Service patchedService = PatchUtils.patch(
                    V1Service.class,
                    () ->
                            coreV1Api.patchNamespacedService(
                                            serviceName,
                                            namespace,
                                            patch)
                                    .buildCall(null),
                    V1Patch.PATCH_FORMAT_JSON_PATCH);

Error: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

Relevant log output
javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
Additional Information

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the PATCH request in the K3S test setup and compare it with the successful namespace and service calls shown in the issue. Trace the SSL and certificate handling used by coreV1Api.patchNamespacedService and PatchUtils.patch; done means the PATCH command succeeds without the PKIX SSLHandshakeException.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, java, kubernetes
Domain
api, infrastructure, testing
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.