<?xml version="1.0" encoding="utf-8"?><testsuites name="pytest tests"><testsuite name="pytest" errors="0" failures="6" skipped="43" tests="184" time="1424.392" timestamp="2026-09-09T20:46:37.700858+00:00" hostname="maas-group-test-8rgps-e2e-maas-openshift-pod"><testcase classname="tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_subscription_namespace_visible_to_api@security" time="0.002"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:214: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_another_namespace_not_visible_to_api@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:247: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_maas_subscription_namespace@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:287: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_another_namespace@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:324: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestModelRef" name="test_auth_policy_model_ref@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:382: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestModelRef" name="test_subscription_model_ref@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:456: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_negative_security.TestAPIKeyManagementIsolation" name="test_api_key_cannot_mint_another_api_key@security" time="0.226" /><testcase classname="tests.test_smoke" name="test_healthz_or_404@readonly" time="0.032" /><testcase classname="tests.test_smoke" name="test_tokens_endpoint_replaced_by_api_keys@readonly" time="0.025" /><testcase classname="tests.test_smoke" name="test_models_catalog@readonly" time="0.034" /><testcase classname="tests.test_smoke" name="test_chat_completions_gateway_alive@readonly" time="0.093" /><testcase classname="tests.test_smoke" name="test_legacy_completions_optionally@readonly" time="0.042" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_forged_identity_headers_rejected_on_key_mint[username-only]@security" time="0.300" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_default_aitenant_bootstraps_maas_tenant_config_without_gateway_mutation@mt_lifecycle" time="1.672" /><testcase classname="tests.test_tenant.TestTenantLifecycle" name="test_tenant_ready_and_phase_healthy@readonly" time="0.346" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_forged_identity_headers_rejected_on_key_mint[group-only]@security" time="0.383" /><testcase classname="tests.test_tenant.TestTenantContract" name="test_status_has_phase_and_conditions@readonly" time="0.137" /><testcase classname="tests.test_tenant.TestTenantContract" name="test_spec_is_well_formed@readonly" time="0.115" /><testcase classname="tests.test_tenant.TestTenantContract" name="test_conditions_use_kubernetes_metav1_shape@readonly" time="0.112" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_injected_identity_headers_rejected_on_inference@security" time="0.206" /><testcase classname="tests.test_tenant.TestTenantNoFalseOwnership" name="test_maas_user_crs_not_owned_by_tenant@readonly" time="0.353" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_duplicate_subscription_headers_ignored@security" time="0.242" /><testcase classname="tests.test_negative_security.TestExpiredKeyRejection" name="test_expired_key_rejected_at_gateway@security" time="5.077" /><testcase classname="tests.test_config_tenant.TestConfigAnchorPresence" name="test_cluster_config_default_exists@readonly" time="0.369" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_rejected_outside_ai_tenants_namespace@mt_lifecycle" time="8.419" /><testcase classname="tests.test_config_tenant.TestConfigAnchorPresence" name="test_cluster_config_not_terminating@readonly" time="0.130" /><testcase classname="tests.test_config_tenant.TestConfigTenantOwnership" name="test_default_aitenant_lists_config_owner_reference@readonly" time="0.107" /><testcase classname="tests.test_config_tenant.TestConfigTenantOwnership" name="test_tenant_config_lists_config_owner_reference@readonly" time="0.106" /><testcase classname="tests.test_config_tenant.TestConfigTenantOwnership" name="test_maas_controller_deployment_does_not_list_config_owner_reference@readonly" time="0.111" /><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_requires_auth@readonly" time="4.108" /><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_with_invalid_token@readonly" time="3.115" /><testcase classname="tests.test_negative_security.TestCrossModelAccess" name="test_key_cannot_access_model_outside_subscription@security" time="36.122" /><testcase classname="tests.test_external_models.TestExternalModelDiscovery" name="test_maasmodelref_created@external" time="7.823" /><testcase classname="tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_httproute@external" time="0.105" /><testcase classname="tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_backend_service@external" time="0.106" /><testcase classname="tests.test_external_models.TestExternalModelAuth" name="test_invalid_key_returns_401@external" time="0.054" /><testcase classname="tests.test_external_models.TestExternalModelAuth" name="test_no_key_returns_401@external" time="0.031" /><testcase classname="tests.test_external_models.TestExternalModelEgress" name="test_request_forwarded_returns_200@external" time="0.109" /><testcase classname="tests.test_external_models.TestExternalModelCleanup" name="test_delete_removes_httproute@external" time="12.600" /><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_authenticated@readonly" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery.py:136: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_gateway_matches_deployment@readonly" time="0.000"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery.py:212: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_not_exposed_through_gateway@readonly" time="0.030" /><testcase classname="tests.test_tenant_auto_resolve.TestTenantAutoResolve" name="test_auto_resolve_populates_resolved_tenant_ref@tenant_auto_resolve" time="183.866" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_create_bootstrap_resources@mt_lifecycle" time="36.408" /><testcase classname="tests.test_external_models.TestExternalModelPathRouting" name="test_wrong_path_returns_not_found@external" time="0.035" /><testcase classname="tests.test_external_models.TestLegacyExternalModelMigration" name="test_migration_sets_legacy_status_and_removes_networking@external" time="3.591" /><testcase classname="tests.test_external_models.TestExternalModelBodyRouting" name="test_correct_model_in_body_succeeds@external" time="0.225" /><testcase classname="tests.test_external_models.TestExternalModelBodyRouting" name="test_wrong_model_in_body_does_not_error@external" time="0.167" /><testcase classname="tests.test_external_models.TestExternalModelBodyRouting" name="test_missing_model_in_body_does_not_error@external" time="1.206" /><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_oidc_token_can_create_api_key@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:252: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_invalid_oidc_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:263: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_empty_bearer_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:277: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_no_auth_header_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:290: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_tampered_expired_oidc_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:303: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_real_expired_oidc_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:335: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenClaims" name="test_token_contains_groups_claim@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:379: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenClaims" name="test_token_contains_preferred_username@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:395: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenClaims" name="test_different_users_have_different_groups@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:405: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiUser" name="test_bob_sre_can_mint_api_key@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:428: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiUser" name="test_wrong_password_gets_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:436: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiUser" name="test_nonexistent_user_gets_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:441: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCModelAccess" name="test_minted_api_key_can_list_models_and_infer@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:454: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCModelAccess" name="test_revoked_api_key_cannot_access_models@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:501: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCModelAccess" name="test_oidc_user_without_group_access_gets_empty_list@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:537: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiTenant" name="test_tenant_b_token_rejected_by_maas@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:602: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiTenant" name="test_tenant_a_users_are_isolated@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:633: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCAPIKeyLifecycle" name="test_create_and_revoke_api_key@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:659: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCAPIKeyLifecycle" name="test_api_key_owner_matches_oidc_username@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:690: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_username_header_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:750: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_group_header_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:786: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_subscription_header_ignored@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:824: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_username_on_oidc_token_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:872: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCClientBinding" name="test_wrong_oauth_client_token_is_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:961: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCGroupSafety" name="test_unsafe_group_name_is_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1013: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCGroupSafety" name="test_mixed_safe_and_unsafe_groups_is_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1049: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCDirectModelAccess" name="test_oidc_token_can_list_models_directly@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1103: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCAlertingInfra" name="test_authorino_prometheusrule_exists@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1142: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_negative_security.TestMissingModelRef" name="test_subscription_with_nonexistent_model_ref@security" time="1.047" /><testcase classname="tests.test_negative_security.TestMissingModelRef" name="test_authpolicy_with_nonexistent_model_ref@security" time="0.655" /><testcase classname="tests.test_negative_security.TestHeaderAbuse" name="test_special_characters_in_subscription_header@security" time="0.312" /><testcase classname="tests.test_negative_security.TestWebhookValidation" name="test_subscription_rejected_in_unlabeled_namespace@security" time="9.827" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_migrates_and_removes_legacy_tenant@mt_lifecycle" time="36.085" /><testcase classname="tests.test_negative_security.TestWebhookValidation" name="test_authpolicy_rejected_in_unlabeled_namespace@security" time="7.608" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_internal_endpoint_not_routable[subscriptions-select]@security" time="0.170" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_internal_endpoint_not_routable[api-keys-cleanup]@security" time="0.152" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_internal_endpoint_not_routable[api-keys-validate]@security" time="0.201" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_health_endpoint_accessible@security" time="0.044" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_v1_models_via_maas_api_prefix@security" time="0.161" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_delete_cleans_maas_resources_and_preserves_user_objects@mt_lifecycle" time="36.155" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_derives_non_default_tenant_namespace@mt_lifecycle" time="35.877" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_labeled_tenant_namespace_is_discovered@mt_lifecycle" time="7.720" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_label_removal_stops_reconciliation@mt_lifecycle" time="32.735" /><testcase classname="tests.test_tenant_auto_resolve.TestTenantAutoResolve" name="test_explicit_tenant_ref_preserved@tenant_auto_resolve" time="195.157" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_unlabeled_namespace_ignored@mt_lifecycle" time="22.102" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_dynamic_discovery_after_label_added@mt_lifecycle" time="17.235" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_per_tenant_oidc_configuration@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="OIDC_ISSUER_URL not set; per-tenant OIDC E2E requires external OIDC deploy">/workspace/source/test/e2e/tests/test_tenant_namespace_discovery.py:189: OIDC_ISSUER_URL not set; per-tenant OIDC E2E requires external OIDC deploy</skipped></testcase><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_namespace_qualified_collision_prevention@mt_lifecycle" time="15.091" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_tenant_admin_rbac_is_namespace_scoped@mt_lifecycle" time="56.193" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantWebhookValidation" name="test_maassubscription_rejected_without_tenant_config_cr@mt_lifecycle" time="6.345" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantWebhookValidation" name="test_maasauthpolicy_rejected_without_tenant_config_cr@mt_lifecycle" time="5.979" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantDiscoveryDormantMode" name="test_dormant_mode_ignores_labeled_namespace@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="Dormant-mode test mutates controller flags; set ENABLE_TENANT_DISCOVERY_DORMANT_E2E=true">/workspace/source/test/e2e/tests/test_tenant_namespace_discovery.py:355: Dormant-mode test mutates controller flags; set ENABLE_TENANT_DISCOVERY_DORMANT_E2E=true</skipped></testcase><testcase classname="tests.test_tenant_namespace_discovery.TestLegacyDefaultNamespaceStillWorks" name="test_models_as_a_service_namespace_reconciles@mt_lifecycle" time="0.554" /><testcase classname="tests.test_tenant_model_inference.TestTenantModelInference" name="test_model_routes_through_tenant_gateway@tenant_isolation" time="337.920" /><testcase classname="tests.test_tenant_model_inference.TestTenantModelInference" name="test_inference_succeeds_through_tenant_gateway@tenant_isolation" time="8.271" /><testcase classname="tests.test_tenant_model_inference.TestTenantModelInference" name="test_tenant_isolation_cross_gateway_blocked@tenant_isolation" time="0.311" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_correct_model_in_body_succeeds@tenant_isolation" time="8.210" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_wrong_model_in_body_rejected@tenant_isolation" time="8.197" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_missing_model_in_body_rejected@tenant_isolation" time="8.182" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_each_tenant_routes_to_own_model@tenant_isolation" time="112.708" /><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_same_tenant_access@mt_lifecycle" time="57.809"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery_isolation.py:133: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_cross_tenant_isolation@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery_isolation.py:181: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_unauthorized_access@mt_lifecycle" time="13.704" /><testcase classname="tests.test_tenant_auto_resolve.TestTenantAutoResolve" name="test_no_matching_tenant_enters_failed@tenant_auto_resolve" time="111.909" /><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_each_tenant_returns_own_gateway@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery_isolation.py:268: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_full_tenant_lifecycle_create_to_delete@mt_lifecycle" time="244.584" /><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_default_tenant_unaffected_by_multitenancy_enablement@mt_lifecycle" time="0.912" /><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_same_named_resources_across_tenants@mt_lifecycle" time="14.744" /><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_tenant_namespace_label_change_triggers_reconciliation@mt_lifecycle" time="37.676" /><testcase classname="tests.test_model_identity_conflict.TestModelIdentityConflictDetection" name="test_colliding_model_names_flagged_then_resolved@models" time="892.789" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_aitenant_creates_dedicated_maas_api_infrastructure@mt_lifecycle" time="59.036" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_tenant_name_environment_variable_set@mt_lifecycle" time="0.211" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_service_routing_isolation@mt_lifecycle" time="0.424" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_httproute_tenant_attachment@mt_lifecycle" time="0.218" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_default_and_multiple_tenants_coexist@mt_lifecycle" time="81.675" /><testcase classname="tests.test_api_keys.TestAPIKeyCRUD" name="test_create_api_key@api_keys" time="772.781" /><testcase classname="tests.test_api_keys.TestAPIKeyCRUD" name="test_list_api_keys@api_keys" time="0.167" /><testcase classname="tests.test_api_keys.TestAPIKeyCRUD" name="test_revoke_api_key@api_keys" time="0.124" /><testcase classname="tests.test_api_keys.TestAPIKeyAuthorization" name="test_admin_manage_other_users_keys@api_keys" time="0.135"><failure message="assert 403 == 200&#10; +  where 403 = &lt;Response [403]&gt;.status_code">self = &lt;test_api_keys.TestAPIKeyAuthorization object at 0x7f35dd3244f0&gt;
api_keys_base_url = 'https://e2e-worker-w0-2b2343.apps.0d83b1d6-1b40-4899-8980-d2ca2f692764.prod.konfluxeaas.com/maas-api/v1/api-keys'
headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6Im1Rbnd5ejFqMkJZRXJZTDZzNnZ4Z2FHdGJFVGRfMlN4ODNGYW5aSWZYdDAifQ.e...dC1JdnfMRh-iEzYvdhAB3SogfQ9SMz-wNbxb2nOu7DjtbATJ8eoPw0tA-lSw4fkZENAW0MYQU1-X3Rz5Q', 'Content-Type': 'application/json'}
admin_headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6Im1Rbnd5ejFqMkJZRXJZTDZzNnZ4Z2FHdGJFVGRfMlN4ODNGYW5aSWZYdDAifQ.e...uMj-CcWYBpvFciiMWxEsZJTHDylB7iKTYq7mmKuffWzdYOgUMrtMEK7RuKGYMoxX8R04NbZgBlx8HQkxA', 'Content-Type': 'application/json'}

    def test_admin_manage_other_users_keys(self, api_keys_base_url: str, headers: dict, admin_headers: dict):
        """Test 4: Admin can manage other user's keys - list and revoke."""
        if not admin_headers:
            pytest.skip("ADMIN_OC_TOKEN not set")
    
        # Create key as regular user
        r_create = requests.post(api_keys_base_url, headers=headers, json={"name": "regular-user-key"}, timeout=30, verify=TLS_VERIFY)
        assert r_create.status_code in (200, 201)
        user_key_id = r_create.json()["id"]
    
        # Get username
        r_get = requests.get(f"{api_keys_base_url}/{user_key_id}", headers=headers, timeout=30, verify=TLS_VERIFY)
        username = r_get.json().get("username") or r_get.json().get("owner")
        assert username
    
        print(f"[admin] User '{username}' created key {user_key_id}")
    
        # Admin lists keys filtered by username using search endpoint
        r_admin = requests.post(
            f"{api_keys_base_url}/search",
            headers=admin_headers,
            json={
                "filters": {"username": username, "status": ["active"]},
                "sort": {"by": "created_at", "order": "desc"},
                "pagination": {"limit": 50, "offset": 0}
            },
            timeout=30,
            verify=TLS_VERIFY
        )
&gt;       assert r_admin.status_code == 200
E       assert 403 == 200
E        +  where 403 = &lt;Response [403]&gt;.status_code

test/e2e/tests/test_api_keys.py:317: AssertionError</failure></testcase><testcase classname="tests.test_api_keys.TestAPIKeyAuthorization" name="test_non_admin_cannot_access_other_users_keys@api_keys" time="0.110" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_own_keys@api_keys" time="0.364" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_other_user_forbidden@api_keys" time="0.030" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_admin_can_revoke_any_user@api_keys" time="0.117"><failure message="assert 403 == 200&#10; +  where 403 = &lt;Response [403]&gt;.status_code">self = &lt;test_api_keys.TestAPIKeyBulkOperations object at 0x7f35dd336550&gt;
api_keys_base_url = 'https://e2e-worker-w0-2b2343.apps.0d83b1d6-1b40-4899-8980-d2ca2f692764.prod.konfluxeaas.com/maas-api/v1/api-keys'
headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6Im1Rbnd5ejFqMkJZRXJZTDZzNnZ4Z2FHdGJFVGRfMlN4ODNGYW5aSWZYdDAifQ.e...dC1JdnfMRh-iEzYvdhAB3SogfQ9SMz-wNbxb2nOu7DjtbATJ8eoPw0tA-lSw4fkZENAW0MYQU1-X3Rz5Q', 'Content-Type': 'application/json'}
admin_headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6Im1Rbnd5ejFqMkJZRXJZTDZzNnZ4Z2FHdGJFVGRfMlN4ODNGYW5aSWZYdDAifQ.e...uMj-CcWYBpvFciiMWxEsZJTHDylB7iKTYq7mmKuffWzdYOgUMrtMEK7RuKGYMoxX8R04NbZgBlx8HQkxA', 'Content-Type': 'application/json'}

    def test_bulk_revoke_admin_can_revoke_any_user(self, api_keys_base_url: str, headers: dict, admin_headers: dict):
        """Test 10: Bulk revoke - admin can bulk revoke any user's keys."""
        if not admin_headers:
            pytest.skip("ADMIN_OC_TOKEN not set")
    
        # Create a key as regular user
        r = requests.post(api_keys_base_url, headers=headers, json={"name": "admin-bulk-revoke-test"}, timeout=30, verify=TLS_VERIFY)
        assert r.status_code in (200, 201)
        key_id = r.json()["id"]
    
        # Get username
        r_get = requests.get(f"{api_keys_base_url}/{key_id}", headers=headers, timeout=30, verify=TLS_VERIFY)
        username = r_get.json().get("username") or r_get.json().get("owner")
        assert username
    
        # Admin bulk revokes user's keys
        r_bulk = requests.post(
            f"{api_keys_base_url}/bulk-revoke",
            headers=admin_headers,
            json={"username": username},
            timeout=30,
            verify=TLS_VERIFY
        )
&gt;       assert r_bulk.status_code == 200
E       assert 403 == 200
E        +  where 403 = &lt;Response [403]&gt;.status_code

test/e2e/tests/test_api_keys.py:425: AssertionError</failure></testcase><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_by_subscription@api_keys" time="1.485"><failure message="assert 403 == 200&#10; +  where 403 = &lt;Response [403]&gt;.status_code">self = &lt;test_api_keys.TestAPIKeyBulkOperations object at 0x7f35dd336f10&gt;
api_keys_base_url = 'https://e2e-worker-w0-2b2343.apps.0d83b1d6-1b40-4899-8980-d2ca2f692764.prod.konfluxeaas.com/maas-api/v1/api-keys'
headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6Im1Rbnd5ejFqMkJZRXJZTDZzNnZ4Z2FHdGJFVGRfMlN4ODNGYW5aSWZYdDAifQ.e...dC1JdnfMRh-iEzYvdhAB3SogfQ9SMz-wNbxb2nOu7DjtbATJ8eoPw0tA-lSw4fkZENAW0MYQU1-X3Rz5Q', 'Content-Type': 'application/json'}
admin_headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6Im1Rbnd5ejFqMkJZRXJZTDZzNnZ4Z2FHdGJFVGRfMlN4ODNGYW5aSWZYdDAifQ.e...uMj-CcWYBpvFciiMWxEsZJTHDylB7iKTYq7mmKuffWzdYOgUMrtMEK7RuKGYMoxX8R04NbZgBlx8HQkxA', 'Content-Type': 'application/json'}

    def test_bulk_revoke_by_subscription(self, api_keys_base_url: str, headers: dict, admin_headers: dict):
        """Admin can bulk revoke all keys bound to a subscription."""
        if not admin_headers:
            pytest.skip("ADMIN_OC_TOKEN not set")
    
        sub_name = f"e2e-bulk-sub-{os.urandom(4).hex()}"
        ns = _ns()
        sa_name = f"e2e-bulk-sa-{os.urandom(4).hex()}"
    
        key_ids = []
        try:
            oc_token = _create_sa_token(sa_name, namespace=MODEL_NAMESPACE)
            sa_user = _sa_to_user(sa_name, namespace=MODEL_NAMESPACE)
            sa_headers = {"Authorization": f"Bearer {oc_token}", "Content-Type": "application/json"}
    
            _create_test_auth_policy(f"{sub_name}-auth", MODEL_REF, users=[sa_user])
            _create_test_subscription(sub_name, MODEL_REF, users=[sa_user])
            _wait_for_maas_subscription_phase(sub_name, namespace=ns)
    
            for i in range(3):
                r = _request_with_gateway_retry(
                    requests.post,
                    api_keys_base_url, headers=sa_headers,
                    json={"name": f"sub-bulk-{i}", "subscription": sub_name},
                    timeout=TIMEOUT, verify=TLS_VERIFY,
                )
                assert r.status_code in (200, 201), f"Failed to create key: {r.text}"
                key_ids.append(r.json()["id"])
    
            r_bulk = requests.post(
                f"{api_keys_base_url}/bulk-revoke",
                headers=admin_headers,
                json={"subscription": sub_name},
                timeout=30, verify=TLS_VERIFY,
            )
&gt;           assert r_bulk.status_code == 200
E           assert 403 == 200
E            +  where 403 = &lt;Response [403]&gt;.status_code

test/e2e/tests/test_api_keys.py:465: AssertionError</failure></testcase><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_by_subscription_forbidden_for_non_admin@api_keys" time="0.036" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_dry_run@api_keys" time="0.222" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_dry_run_by_subscription@api_keys" time="1.336"><failure message="assert 403 == 200&#10; +  where 403 = &lt;Response [403]&gt;.status_code">self = &lt;test_api_keys.TestAPIKeyBulkOperations object at 0x7f35dd3367c0&gt;
api_keys_base_url = 'https://e2e-worker-w0-2b2343.apps.0d83b1d6-1b40-4899-8980-d2ca2f692764.prod.konfluxeaas.com/maas-api/v1/api-keys'
headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6Im1Rbnd5ejFqMkJZRXJZTDZzNnZ4Z2FHdGJFVGRfMlN4ODNGYW5aSWZYdDAifQ.e...dC1JdnfMRh-iEzYvdhAB3SogfQ9SMz-wNbxb2nOu7DjtbATJ8eoPw0tA-lSw4fkZENAW0MYQU1-X3Rz5Q', 'Content-Type': 'application/json'}
admin_headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6Im1Rbnd5ejFqMkJZRXJZTDZzNnZ4Z2FHdGJFVGRfMlN4ODNGYW5aSWZYdDAifQ.e...uMj-CcWYBpvFciiMWxEsZJTHDylB7iKTYq7mmKuffWzdYOgUMrtMEK7RuKGYMoxX8R04NbZgBlx8HQkxA', 'Content-Type': 'application/json'}

    def test_bulk_revoke_dry_run_by_subscription(self, api_keys_base_url: str, headers: dict, admin_headers: dict):
        """Admin dry-run by subscription returns correct key count."""
        if not admin_headers:
            pytest.skip("ADMIN_OC_TOKEN not set")
    
        sub_name = f"e2e-dry-sub-{os.urandom(4).hex()}"
        ns = _ns()
        sa_name = f"e2e-dry-sa-{os.urandom(4).hex()}"
    
        key_ids = []
        try:
            oc_token = _create_sa_token(sa_name, namespace=MODEL_NAMESPACE)
            sa_user = _sa_to_user(sa_name, namespace=MODEL_NAMESPACE)
            sa_headers = {"Authorization": f"Bearer {oc_token}", "Content-Type": "application/json"}
    
            _create_test_auth_policy(f"{sub_name}-auth", MODEL_REF, users=[sa_user])
            _create_test_subscription(sub_name, MODEL_REF, users=[sa_user])
            _wait_for_maas_subscription_phase(sub_name, namespace=ns)
    
            for i in range(2):
                r = _request_with_gateway_retry(
                    requests.post,
                    api_keys_base_url, headers=sa_headers,
                    json={"name": f"dry-sub-{i}", "subscription": sub_name},
                    timeout=TIMEOUT, verify=TLS_VERIFY,
                )
                assert r.status_code in (200, 201)
                key_ids.append(r.json()["id"])
    
            r_dry = requests.post(
                f"{api_keys_base_url}/bulk-revoke",
                headers=admin_headers,
                json={"subscription": sub_name, "dryRun": True},
                timeout=30, verify=TLS_VERIFY,
            )
&gt;           assert r_dry.status_code == 200
E           assert 403 == 200
E            +  where 403 = &lt;Response [403]&gt;.status_code

test/e2e/tests/test_api_keys.py:574: AssertionError</failure></testcase><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_combined_user_and_subscription@api_keys" time="25.612"><failure message="assert 403 == 200&#10; +  where 403 = &lt;Response [403]&gt;.status_code">self = &lt;test_api_keys.TestAPIKeyBulkOperations object at 0x7f35dd319d90&gt;
api_keys_base_url = 'https://e2e-worker-w0-2b2343.apps.0d83b1d6-1b40-4899-8980-d2ca2f692764.prod.konfluxeaas.com/maas-api/v1/api-keys'
headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6Im1Rbnd5ejFqMkJZRXJZTDZzNnZ4Z2FHdGJFVGRfMlN4ODNGYW5aSWZYdDAifQ.e...dC1JdnfMRh-iEzYvdhAB3SogfQ9SMz-wNbxb2nOu7DjtbATJ8eoPw0tA-lSw4fkZENAW0MYQU1-X3Rz5Q', 'Content-Type': 'application/json'}
admin_headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6Im1Rbnd5ejFqMkJZRXJZTDZzNnZ4Z2FHdGJFVGRfMlN4ODNGYW5aSWZYdDAifQ.e...uMj-CcWYBpvFciiMWxEsZJTHDylB7iKTYq7mmKuffWzdYOgUMrtMEK7RuKGYMoxX8R04NbZgBlx8HQkxA', 'Content-Type': 'application/json'}

    def test_bulk_revoke_combined_user_and_subscription(self, api_keys_base_url: str, headers: dict, admin_headers: dict):
        """Admin can revoke keys for a specific user within a specific subscription.
    
        Negative control: a second user's keys in the same subscription must remain active.
        """
        if not admin_headers:
            pytest.skip("ADMIN_OC_TOKEN not set")
    
        sub_name = f"e2e-combo-sub-{os.urandom(4).hex()}"
        ns = _ns()
        sa_name = f"e2e-combo-sa-{os.urandom(4).hex()}"
        sa2_name = f"e2e-combo-sa2-{os.urandom(4).hex()}"
    
        key_ids = []
        key_ids_user2 = []
        try:
            oc_token = _create_sa_token(sa_name, namespace=MODEL_NAMESPACE)
            sa_user = _sa_to_user(sa_name, namespace=MODEL_NAMESPACE)
            sa_headers = {"Authorization": f"Bearer {oc_token}", "Content-Type": "application/json"}
    
            oc_token2 = _create_sa_token(sa2_name, namespace=MODEL_NAMESPACE)
            sa_user2 = _sa_to_user(sa2_name, namespace=MODEL_NAMESPACE)
            sa2_headers = {"Authorization": f"Bearer {oc_token2}", "Content-Type": "application/json"}
    
            _create_test_auth_policy(f"{sub_name}-auth", MODEL_REF, users=[sa_user, sa_user2])
            _create_test_subscription(sub_name, MODEL_REF, users=[sa_user, sa_user2])
            _wait_for_maas_subscription_phase(sub_name, namespace=ns)
    
            for i in range(2):
                r = _request_with_gateway_retry(
                    requests.post,
                    api_keys_base_url, headers=sa_headers,
                    json={"name": f"combined-{i}", "subscription": sub_name},
                    timeout=TIMEOUT, verify=TLS_VERIFY,
                )
                assert r.status_code in (200, 201)
                key_ids.append(r.json()["id"])
    
            r_u2 = _request_with_gateway_retry(
                requests.post,
                api_keys_base_url, headers=sa2_headers,
                json={"name": "user2-key", "subscription": sub_name},
                timeout=TIMEOUT, verify=TLS_VERIFY,
            )
            assert r_u2.status_code in (200, 201)
            key_ids_user2.append(r_u2.json()["id"])
    
            r_get = requests.get(f"{api_keys_base_url}/{key_ids[0]}", headers=sa_headers, timeout=30, verify=TLS_VERIFY)
            username = r_get.json().get("username") or r_get.json().get("owner")
            assert username
    
            r_bulk = requests.post(
                f"{api_keys_base_url}/bulk-revoke",
                headers=admin_headers,
                json={"username": username, "subscription": sub_name},
                timeout=30, verify=TLS_VERIFY,
            )
&gt;           assert r_bulk.status_code == 200
E           assert 403 == 200
E            +  where 403 = &lt;Response [403]&gt;.status_code

test/e2e/tests/test_api_keys.py:651: AssertionError</failure></testcase><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_creation_scoped_to_tenant@tenant_isolation" time="314.960" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_validates_against_correct_tenant@tenant_isolation" time="46.982" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_rejected_cross_tenant@tenant_isolation" time="25.752" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_oidc_token_validation_per_tenant@tenant_isolation" time="0.001"><skipped type="pytest.skip" message="Per-tenant OIDC tokens unavailable — set OIDC_TOKEN_URL (tenant-a) and OIDC_TOKEN_URL_TENANT_B (tenant-b), or OIDC_TOKEN_TENANT_A / OIDC_TOKEN_TENANT_B">/workspace/source/test/e2e/tests/test_tenant_auth_isolation.py:215: Per-tenant OIDC tokens unavailable — set OIDC_TOKEN_URL (tenant-a) and OIDC_TOKEN_URL_TENANT_B (tenant-b), or OIDC_TOKEN_TENANT_A / OIDC_TOKEN_TENANT_B</skipped></testcase><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_explicit_subscription_header@models" time="1.298" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_empty_subscription_header_value@models" time="0.435" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_models_filtered_by_subscription@models" time="0.876" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_deduplication_same_model_multiple_refs@models" time="12.022" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_list_scoped_to_tenant@tenant_isolation" time="30.024" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_multiple_distinct_models_in_subscription@models" time="10.309" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_user_token_returns_all_models@models" time="13.332" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_metadata_not_leaked_cross_tenant@tenant_isolation" time="29.079" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_user_token_with_subscription_header_filters@models" time="1.435" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_response_schema_matches_openapi@models" time="0.383" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_model_metadata_preserved@models" time="0.386" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_scoped_to_subscription@models" time="1.464" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_with_deleted_subscription_403@models" time="1.472" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_with_inaccessible_subscription_403@models" time="1.838" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_invalid_subscription_header_403@models" time="1.535" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_access_denied_to_subscription_403@models" time="2.270" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_ignores_subscription_header@models" time="20.743" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_subscription_selection_uses_tenant_namespace@tenant_isolation" time="29.484" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_multiple_api_keys_different_subscriptions@models" time="10.905"><failure message="AssertionError: Key2 should see publishers/e2e-models-e2e-worker-w4-933e9d/models/e2e/distinct-2-w4-933e9d from e2e-multi-keys-sub2&#10;assert 'publishers/e2e-models-e2e-worker-w4-933e9d/models/e2e/distinct-2-w4-933e9d' in set()">self = &lt;test_models_endpoint.TestModelsEndpoint object at 0x7f0e2c2553d0&gt;

    def test_multiple_api_keys_different_subscriptions(self):
        """
        Test: Multiple API keys each bound to different subscriptions.
    
        Creates two API keys from the same user, each explicitly bound to a different
        subscription. Verifies each key returns only its bound subscription's models.
    
        Expected: Each API key returns models only from its bound subscription.
        """
        sa_name = "e2e-multi-keys-sa"
        sa_ns = "default"
        maas_ns = _ns()
        sub1_name = "e2e-multi-keys-sub1"
        sub2_name = "e2e-multi-keys-sub2"
        auth1_name = "e2e-multi-keys-auth1"
        auth2_name = "e2e-multi-keys-auth2"
        api_key1 = None
        api_key2 = None
    
        try:
            # Create SA
            sa_token = _create_sa_token(sa_name, namespace=sa_ns)
            sa_user = _sa_to_user(sa_name, namespace=sa_ns)
    
            # Create two subscriptions with different models
            log.info(f"Creating subscription 1 with {DISTINCT_MODEL_REF}")
            _create_test_auth_policy(auth1_name, DISTINCT_MODEL_REF, users=[sa_user])
            _create_test_subscription(sub1_name, DISTINCT_MODEL_REF, users=[sa_user])
    
            log.info(f"Creating subscription 2 with {DISTINCT_MODEL_2_REF}")
            _create_test_auth_policy(auth2_name, DISTINCT_MODEL_2_REF, users=[sa_user])
            _create_test_subscription(sub2_name, DISTINCT_MODEL_2_REF, users=[sa_user])
    
            # Wait for both subscriptions to reconcile before creating API keys
            _wait_for_maas_subscription_phase(sub1_name, namespace=maas_ns)
            _wait_for_maas_subscription_phase(sub2_name, namespace=maas_ns)
    
            # Create two API keys, each bound to a different subscription
            log.info(f"Creating API key 1 bound to {sub1_name}")
            api_key1_response = _request_with_gateway_retry(
                requests.post,
                f"{_maas_api_url()}/v1/api-keys",
                headers={"Authorization": f"Bearer {sa_token}", "Content-Type": "application/json"},
                json={"name": "key1", "subscription": sub1_name},
            )
            assert api_key1_response.status_code in (200, 201)
            api_key1 = api_key1_response.json().get("key")
            bound_sub1 = api_key1_response.json().get("subscription")
            assert bound_sub1 == sub1_name, f"Key 1 should be bound to {sub1_name}, got {bound_sub1}"
    
            log.info(f"Creating API key 2 bound to {sub2_name}")
            api_key2_response = _request_with_gateway_retry(
                requests.post,
                f"{_maas_api_url()}/v1/api-keys",
                headers={"Authorization": f"Bearer {sa_token}", "Content-Type": "application/json"},
                json={"name": "key2", "subscription": sub2_name},
            )
            assert api_key2_response.status_code in (200, 201)
            api_key2 = api_key2_response.json().get("key")
            bound_sub2 = api_key2_response.json().get("subscription")
            assert bound_sub2 == sub2_name, f"Key 2 should be bound to {sub2_name}, got {bound_sub2}"
    
            _wait_for_maas_auth_policy_phase(auth1_name, require_enforced=False)
            _wait_for_maas_auth_policy_phase(auth2_name, require_enforced=False)
    
            # Test key1 - should return models from sub1 only
            log.info(f"Testing API key 1 (bound to {sub1_name})")
            r1 = _get_models_with_gateway_retry(
                headers={"Authorization": f"Bearer {api_key1}"},
            )
            assert r1.status_code == 200, f"Expected 200 for key1, got {r1.status_code}: {r1.text}"
            models1 = r1.json().get("data") or []
            model_ids1 = {m["id"] for m in models1}
    
            assert DISTINCT_MODEL_ID in model_ids1, f"Key1 should see {DISTINCT_MODEL_ID} from {sub1_name}"
            assert DISTINCT_MODEL_2_ID not in model_ids1, f"Key1 should NOT see {DISTINCT_MODEL_2_ID} from {sub2_name}"
    
            # Test key2 - should return models from sub2 only
            log.info(f"Testing API key 2 (bound to {sub2_name})")
            r2 = _get_models_with_gateway_retry(
                headers={"Authorization": f"Bearer {api_key2}"},
            )
            assert r2.status_code == 200, f"Expected 200 for key2, got {r2.status_code}: {r2.text}"
            models2 = r2.json().get("data") or []
            model_ids2 = {m["id"] for m in models2}
    
&gt;           assert DISTINCT_MODEL_2_ID in model_ids2, f"Key2 should see {DISTINCT_MODEL_2_ID} from {sub2_name}"
E           AssertionError: Key2 should see publishers/e2e-models-e2e-worker-w4-933e9d/models/e2e/distinct-2-w4-933e9d from e2e-multi-keys-sub2
E           assert 'publishers/e2e-models-e2e-worker-w4-933e9d/models/e2e/distinct-2-w4-933e9d' in set()

test/e2e/tests/test_models_endpoint.py:2062: AssertionError</failure></testcase><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_service_account_token_multiple_subs_no_header@models" time="13.229" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_service_account_token_multiple_subs_with_header@models" time="8.951" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_unauthenticated_request_401@models" time="0.028" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyStructure" name="test_target_ref_points_to_gateway@models" time="0.220" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyStructure" name="test_no_per_model_authpolicy_for_fixture_model@models" time="0.103" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyLifecycle" name="test_gateway_auth_rego_is_fixed_size@models" time="3.236" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyLifecycle" name="test_only_one_gateway_authpolicy_named_maas_gateway_auth@models" time="0.234" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyManagementEndpointAccess" name="test_gateway_auth_group_membership_has_when_guard@models" time="0.120" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyManagementEndpointAccess" name="test_gateway_auth_subscription_check_gated_by_model_identity@models" time="0.110" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyManagementEndpointAccess" name="test_gateway_default_auth_scoped_if_present@models" time="23.332"><skipped type="pytest.skip" message="legacy gateway-default-auth is scoped to the shared default gateway">/workspace/source/test/e2e/tests/test_gateway_scoped_authpolicy.py:219: legacy gateway-default-auth is scoped to the shared default gateway</skipped></testcase><testcase classname="tests.test_tenant_subscription_isolation.TestTenantSubscriptionIsolation" name="test_subscription_list_scoped_to_tenant@tenant_isolation" time="81.096" /><testcase classname="tests.test_tenant_subscription_isolation.TestTenantSubscriptionIsolation" name="test_subscription_selection_per_tenant@tenant_isolation" time="30.057" /><testcase classname="tests.test_tenant_rate_limit_isolation.TestTenantRateLimitIsolation" name="test_rate_limit_enforced_per_tenant@tenant_isolation" time="62.191" /><testcase classname="tests.test_tenant_rate_limit_isolation.TestTenantRateLimitIsolation" name="test_independent_tenant_rate_limits@tenant_isolation" time="12.443" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_per_tenant_ipp_deployments_exist@tenant_isolation" time="58.762" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_per_tenant_ipp_env_vars@tenant_isolation" time="0.210" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_per_tenant_envoyfilter_workload_selector_isolated@tenant_isolation" time="0.327" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_per_tenant_envoyfilter_grpc_clusters@tenant_isolation" time="0.209" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_default_tenant_keeps_legacy_ipp_names@tenant_isolation" time="0.203" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_multiple_tenant_ipp_stacks_coexist@tenant_isolation" time="0.313" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_per_tenant_networkpolicy_when_applied@tenant_isolation" time="0.217" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPRouting" name="test_default_gateway_hits_default_ipp_only@tenant_isolation" time="2.508" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPRouting" name="test_tenant_gateway_hits_tenant_ipp_only@tenant_isolation" time="26.582" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPCleanup" name="test_ipp_resources_removed_on_aitenant_delete@tenant_isolation" time="186.996" /></testsuite></testsuites>