<?xml version="1.0" encoding="utf-8"?><testsuites name="pytest tests"><testsuite name="pytest" errors="5" failures="13" skipped="43" tests="176" time="2074.242" timestamp="2026-09-15T12:58:09.746601+00:00" hostname="maas-group-test-l8rk2-e2e-maas-openshift-pod"><testcase classname="tests.test_smoke" name="test_healthz_or_404@readonly" time="0.028" /><testcase classname="tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_subscription_namespace_visible_to_api@security" time="0.005"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:214: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_another_namespace_not_visible_to_api@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:247: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_maas_subscription_namespace@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:287: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_another_namespace@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:324: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestModelRef" name="test_auth_policy_model_ref@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:382: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestModelRef" name="test_subscription_model_ref@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:456: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_negative_security.TestAPIKeyManagementIsolation" name="test_api_key_cannot_mint_another_api_key@security" time="0.223" /><testcase classname="tests.test_smoke" name="test_tokens_endpoint_replaced_by_api_keys@readonly" time="0.027" /><testcase classname="tests.test_smoke" name="test_models_catalog@readonly" time="0.036" /><testcase classname="tests.test_smoke" name="test_chat_completions_gateway_alive@readonly" time="0.079" /><testcase classname="tests.test_smoke" name="test_legacy_completions_optionally@readonly" time="0.042" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_forged_identity_headers_rejected_on_key_mint[username-only]@security" time="0.274" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_default_aitenant_bootstraps_maas_tenant_config_without_gateway_mutation@mt_lifecycle" time="1.604" /><testcase classname="tests.test_tenant.TestTenantLifecycle" name="test_tenant_ready_and_phase_healthy@readonly" time="0.356" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_forged_identity_headers_rejected_on_key_mint[group-only]@security" time="0.303" /><testcase classname="tests.test_tenant.TestTenantContract" name="test_status_has_phase_and_conditions@readonly" time="0.118" /><testcase classname="tests.test_tenant.TestTenantContract" name="test_spec_is_well_formed@readonly" time="0.128" /><testcase classname="tests.test_tenant.TestTenantContract" name="test_conditions_use_kubernetes_metav1_shape@readonly" time="0.120" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_injected_identity_headers_rejected_on_inference@security" time="0.193" /><testcase classname="tests.test_tenant.TestTenantNoFalseOwnership" name="test_maas_user_crs_not_owned_by_tenant@readonly" time="0.327" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_duplicate_subscription_headers_ignored@security" time="0.231" /><testcase classname="tests.test_negative_security.TestExpiredKeyRejection" name="test_expired_key_rejected_at_gateway@security" time="5.503" /><testcase classname="tests.test_config_tenant.TestConfigAnchorPresence" name="test_cluster_config_default_exists@readonly" time="0.377" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_rejected_outside_ai_tenants_namespace@mt_lifecycle" time="8.256" /><testcase classname="tests.test_config_tenant.TestConfigAnchorPresence" name="test_cluster_config_not_terminating@readonly" time="0.134" /><testcase classname="tests.test_config_tenant.TestConfigTenantOwnership" name="test_default_aitenant_lists_config_owner_reference@readonly" time="0.112" /><testcase classname="tests.test_config_tenant.TestConfigTenantOwnership" name="test_tenant_config_lists_config_owner_reference@readonly" time="0.111" /><testcase classname="tests.test_config_tenant.TestConfigTenantOwnership" name="test_maas_controller_deployment_does_not_list_config_owner_reference@readonly" time="0.118" /><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_requires_auth@readonly" time="8.518" /><testcase classname="tests.test_negative_security.TestCrossModelAccess" name="test_key_cannot_access_model_outside_subscription@security" time="40.344" /><testcase classname="tests.test_external_models.TestExternalModelDiscovery" name="test_maasmodelref_created@external" time="7.790" /><testcase classname="tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_httproute@external" time="0.100" /><testcase classname="tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_backend_service@external" time="0.106" /><testcase classname="tests.test_external_models.TestExternalModelAuth" name="test_invalid_key_returns_401@external" time="0.036" /><testcase classname="tests.test_external_models.TestExternalModelAuth" name="test_no_key_returns_401@external" time="0.028" /><testcase classname="tests.test_external_models.TestExternalModelEgress" name="test_request_forwarded_returns_200@external" time="1.461" /><testcase classname="tests.test_external_models.TestExternalModelCleanup" name="test_delete_removes_httproute@external" time="12.624" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_create_bootstrap_resources@mt_lifecycle" time="39.789" /><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_with_invalid_token@readonly" time="2.000" /><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_authenticated@readonly" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery.py:79: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_gateway_matches_deployment@readonly" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery.py:155: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_not_exposed_through_gateway@readonly" time="0.033" /><testcase classname="tests.test_tenant_auto_resolve.TestTenantAutoResolve" name="test_auto_resolve_populates_resolved_tenant_ref@tenant_auto_resolve" time="197.528" /><testcase classname="tests.test_external_models.TestExternalModelPathRouting" name="test_wrong_path_returns_not_found@external" time="0.029" /><testcase classname="tests.test_external_models.TestLegacyExternalModelMigration" name="test_migration_sets_legacy_status_and_removes_networking@external" time="3.595" /><testcase classname="tests.test_external_models.TestExternalModelBodyRouting" name="test_correct_model_in_body_succeeds@external" time="1.287" /><testcase classname="tests.test_external_models.TestExternalModelBodyRouting" name="test_wrong_model_in_body_does_not_error@external" time="0.706" /><testcase classname="tests.test_external_models.TestExternalModelBodyRouting" name="test_missing_model_in_body_does_not_error@external" time="33.015" /><testcase classname="tests.test_negative_security.TestMissingModelRef" name="test_subscription_with_nonexistent_model_ref@security" time="30.943" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_migrates_and_removes_legacy_tenant@mt_lifecycle" time="36.097" /><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_oidc_token_can_create_api_key@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:252: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_invalid_oidc_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:263: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_empty_bearer_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:277: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_no_auth_header_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:290: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_tampered_expired_oidc_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:303: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_real_expired_oidc_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:335: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenClaims" name="test_token_contains_groups_claim@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:379: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenClaims" name="test_token_contains_preferred_username@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:395: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenClaims" name="test_different_users_have_different_groups@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:405: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiUser" name="test_bob_sre_can_mint_api_key@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:428: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiUser" name="test_wrong_password_gets_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:436: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiUser" name="test_nonexistent_user_gets_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:441: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCModelAccess" name="test_minted_api_key_can_list_models_and_infer@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:454: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCModelAccess" name="test_revoked_api_key_cannot_access_models@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:501: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCModelAccess" name="test_oidc_user_without_group_access_gets_empty_list@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:537: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiTenant" name="test_tenant_b_token_rejected_by_maas@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:602: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiTenant" name="test_tenant_a_users_are_isolated@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:633: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCAPIKeyLifecycle" name="test_create_and_revoke_api_key@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:659: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCAPIKeyLifecycle" name="test_api_key_owner_matches_oidc_username@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:690: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_username_header_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:750: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_group_header_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:786: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_subscription_header_ignored@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:824: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_username_on_oidc_token_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:872: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCClientBinding" name="test_wrong_oauth_client_token_is_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:961: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCGroupSafety" name="test_unsafe_group_name_is_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1013: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCGroupSafety" name="test_mixed_safe_and_unsafe_groups_is_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1049: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCDirectModelAccess" name="test_oidc_token_can_list_models_directly@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1103: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCAlertingInfra" name="test_authorino_prometheusrule_exists@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1142: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_negative_security.TestMissingModelRef" name="test_authpolicy_with_nonexistent_model_ref@security" time="2.775" /><testcase classname="tests.test_negative_security.TestHeaderAbuse" name="test_special_characters_in_subscription_header@security" time="0.363" /><testcase classname="tests.test_negative_security.TestWebhookValidation" name="test_subscription_rejected_in_unlabeled_namespace@security" time="7.173" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_delete_cleans_maas_resources_and_preserves_user_objects@mt_lifecycle" time="36.978" /><testcase classname="tests.test_negative_security.TestWebhookValidation" name="test_authpolicy_rejected_in_unlabeled_namespace@security" time="7.124" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_internal_endpoint_not_routable[subscriptions-select]@security" time="0.139" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_internal_endpoint_not_routable[api-keys-cleanup]@security" time="0.149" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_internal_endpoint_not_routable[api-keys-validate]@security" time="0.165" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_health_endpoint_accessible@security" time="0.026" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_v1_models_via_maas_api_prefix@security" time="0.141" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_derives_non_default_tenant_namespace@mt_lifecycle" time="38.398" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_labeled_tenant_namespace_is_discovered@mt_lifecycle" time="121.908" /><testcase classname="tests.test_tenant_auto_resolve.TestTenantAutoResolve" name="test_explicit_tenant_ref_preserved@tenant_auto_resolve" time="135.069" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_label_removal_stops_reconciliation@mt_lifecycle" time="33.456" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_unlabeled_namespace_ignored@mt_lifecycle" time="23.065" /><testcase classname="tests.test_tenant_model_inference.TestTenantModelInference" name="test_model_routes_through_tenant_gateway@tenant_isolation" time="327.411" /><testcase classname="tests.test_tenant_model_inference.TestTenantModelInference" name="test_inference_succeeds_through_tenant_gateway@tenant_isolation" time="8.283" /><testcase classname="tests.test_model_identity_conflict.TestModelIdentityConflictDetection" name="test_colliding_model_names_flagged_then_resolved@models" time="405.543" /><testcase classname="tests.test_api_keys.TestAPIKeyCRUD" name="test_create_api_key@api_keys" time="330.152" /><testcase classname="tests.test_api_keys.TestAPIKeyCRUD" name="test_list_api_keys@api_keys" time="0.129" /><testcase classname="tests.test_api_keys.TestAPIKeyCRUD" name="test_revoke_api_key@api_keys" time="0.097" /><testcase classname="tests.test_api_keys.TestAPIKeyAuthorization" name="test_admin_manage_other_users_keys@api_keys" time="0.589" /><testcase classname="tests.test_api_keys.TestAPIKeyAuthorization" name="test_non_admin_cannot_access_other_users_keys@api_keys" time="0.088" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_own_keys@api_keys" time="0.246" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_other_user_forbidden@api_keys" time="0.033" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_admin_can_revoke_any_user@api_keys" time="0.094" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_by_subscription@api_keys" time="31.421" /><testcase classname="tests.test_tenant_model_inference.TestTenantModelInference" name="test_tenant_isolation_cross_gateway_blocked@tenant_isolation" time="0.347" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_correct_model_in_body_succeeds@tenant_isolation" time="8.203" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_dynamic_discovery_after_label_added@mt_lifecycle" time="19.771" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_wrong_model_in_body_rejected@tenant_isolation" time="8.207" /><testcase classname="tests.test_tenant_auto_resolve.TestTenantAutoResolve" name="test_no_matching_tenant_enters_failed@tenant_auto_resolve" time="73.678" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_missing_model_in_body_rejected@tenant_isolation" time="8.213" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_per_tenant_oidc_configuration@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="OIDC_ISSUER_URL not set; per-tenant OIDC E2E requires external OIDC deploy">/workspace/source/test/e2e/tests/test_tenant_namespace_discovery.py:189: OIDC_ISSUER_URL not set; per-tenant OIDC E2E requires external OIDC deploy</skipped></testcase><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_namespace_qualified_collision_prevention@mt_lifecycle" time="243.165" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_each_tenant_routes_to_own_model@tenant_isolation" time="625.588" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_by_subscription_forbidden_for_non_admin@api_keys" time="0.040" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_dry_run@api_keys" time="0.211" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_dry_run_by_subscription@api_keys" time="91.771"><failure message="TimeoutError: MaaSSubscription e2e-dry-sub-19668017 did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)">self = &lt;test_api_keys.TestAPIKeyBulkOperations object at 0x7fc421f44d30&gt;
api_keys_base_url = 'https://e2e-worker-w0-6c9f0b.apps.de6489af-f880-4a63-b730-0004b3480260.prod.konfluxeaas.com/maas-api/v1/api-keys'
headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6ImNTakY1UUg2dTMxbnR3bTJrVkluSjhTZzNyaG83TmRJbWxKckVQWG9LUHcifQ.e...ghvKLGgNW-681roiUKvymiuB58tMqKB-ARgTgYhBRxYCX3pRpb6-ztqCVJcznXQ4Z8gV_XFkxauO_-Y2g', 'Content-Type': 'application/json'}
admin_headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6ImNTakY1UUg2dTMxbnR3bTJrVkluSjhTZzNyaG83TmRJbWxKckVQWG9LUHcifQ.e...5gNfJ-jQWGoz6DyMZ_LEtpeyyxFCy_zDFGWahZO2mEDFDZ9rWbKMK0dRvivn0xd6HfWB8f8-KV9XRAj8g', 'Content-Type': 'application/json'}

    def test_bulk_revoke_dry_run_by_subscription(self, api_keys_base_url: str, headers: dict, admin_headers: dict):
        """Admin dry-run by subscription returns correct key count."""
        if not admin_headers:
            pytest.skip("ADMIN_OC_TOKEN not set")
    
        sub_name = f"e2e-dry-sub-{os.urandom(4).hex()}"
        ns = _ns()
        sa_name = f"e2e-dry-sa-{os.urandom(4).hex()}"
    
        key_ids = []
        try:
            oc_token = _create_sa_token(sa_name, namespace=MODEL_NAMESPACE)
            sa_user = _sa_to_user(sa_name, namespace=MODEL_NAMESPACE)
            sa_headers = {"Authorization": f"Bearer {oc_token}", "Content-Type": "application/json"}
    
            _create_test_auth_policy(f"{sub_name}-auth", MODEL_REF, users=[sa_user])
            _create_test_subscription(sub_name, MODEL_REF, users=[sa_user])
&gt;           _wait_for_maas_subscription_phase(sub_name, namespace=ns)

test/e2e/tests/test_api_keys.py:609: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

name = 'e2e-dry-sub-19668017', expected_phase = 'Active'
namespace = 'ai-tenant-e2e-worker-w0-6c9f0b', timeout = 90
require_model_statuses = False

    def _wait_for_maas_subscription_phase(name, expected_phase="Active", namespace=None, timeout=MAAS_SUBSCRIPTION_PHASE_TIMEOUT, require_model_statuses=False):
        """Wait for MaaSSubscription to reach a specific phase.
    
        Args:
            name: Name of the MaaSSubscription
            expected_phase: Phase to wait for (default: "Active")
            namespace: Namespace (defaults to _ns())
            timeout: Maximum wait time in seconds (default: 60)
            require_model_statuses: If True, also requires modelRefStatuses to be populated
                                    (default: False). Set to True for status reporting tests.
    
        Returns:
            The subscription CR dict when the expected phase is reached
    
        Raises:
            TimeoutError: If MaaSSubscription doesn't reach expected phase within timeout
        """
        namespace = namespace or _ns()
        deadline = time.time() + timeout
        log.info(f"Waiting for MaaSSubscription {name} to reach phase '{expected_phase}' (timeout: {timeout}s)...")
    
        while time.time() &lt; deadline:
            cr = _get_cr("maassubscription", name, namespace)
            if cr:
                status = cr.get("status", {})
                phase = status.get("phase")
                model_statuses = status.get("modelRefStatuses", [])
    
                if phase == expected_phase:
                    if require_model_statuses:
                        expected_count = len(cr.get("spec", {}).get("modelRefs", []))
                        if len(model_statuses) &gt;= expected_count:
                            log.info(f"MaaSSubscription {name} reached phase '{expected_phase}' with {len(model_statuses)}/{expected_count} modelRefStatuses")
                            return cr
                    else:
                        log.info(f"MaaSSubscription {name} reached phase '{expected_phase}'")
                        return cr
                log.debug(f"MaaSSubscription {name}: phase={phase}, modelRefStatuses={len(model_statuses)}")
            time.sleep(2)
    
        # Timeout - return current state for debugging
        cr = _get_cr("maassubscription", name, namespace)
        status = cr.get("status", {}) if cr else {}
&gt;       raise TimeoutError(
            f"MaaSSubscription {name} did not reach phase '{expected_phase}' within {timeout}s "
            f"(current: phase={status.get('phase')}, modelRefStatuses={len(status.get('modelRefStatuses', []))})"
        )
E       TimeoutError: MaaSSubscription e2e-dry-sub-19668017 did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)

test/e2e/tests/test_helper.py:1334: TimeoutError</failure></testcase><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_explicit_subscription_header@models" time="44.200" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_empty_subscription_header_value@models" time="0.389" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_models_filtered_by_subscription@models" time="0.845" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_deduplication_same_model_multiple_refs@models" time="91.878"><failure message="TimeoutError: MaaSSubscription e2e-dedup-subscription did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)">self = &lt;test_models_endpoint.TestModelsEndpoint object at 0x7fe0cf0fb610&gt;

    def test_deduplication_same_model_multiple_refs(self):
        """
        Test 6: Same modelRef listed twice should deduplicate to 1 entry.
    
        Creates a subscription with the SAME modelRef listed TWICE (different rate limits).
        The API deduplicates by (model ID, URL) and returns only 1 entry since both
        references point to the same backend service.
    
        The response includes subscription information showing which subscription(s)
        provide access to the model.
        """
        log.info("Test 6: Same modelRef twice should deduplicate (INTENDED behavior)")
    
        sa_name = "e2e-models-dedup-sa"
        sa_ns = "default"
        maas_ns = _ns()
        subscription_name = "e2e-dedup-subscription"
        auth_policy_name = "e2e-dedup-auth"
        api_key = None
    
        try:
            # Create SA with its own token
            sa_token = _create_sa_token(sa_name, namespace=sa_ns)
            sa_user = _sa_to_user(sa_name, namespace=sa_ns)
    
            # Create auth policy that grants access to the model
            log.info(f"Creating auth policy with access to {MODEL_REF}")
            auth_policy_cr = {
                "apiVersion": "maas.opendatahub.io/v1alpha1",
                "kind": "MaaSAuthPolicy",
                "metadata": {
                    "name": auth_policy_name,
                    "namespace": maas_ns,
                },
                "spec": {
                    "modelRefs": [{"name": MODEL_REF, "namespace": MODEL_NAMESPACE}],
                    "subjects": {
                        "users": [sa_user],
                        "groups": [],
                    },
                },
            }
            subprocess.run(
                ["oc", "apply", "-f", "-"],
                input=json.dumps(auth_policy_cr),
                text=True,
                check=True,
            )
    
            # Create subscription with the SAME model ref TWICE (guaranteed duplicates)
            log.info(f"Creating subscription with {MODEL_REF} listed twice (to test deduplication)")
            subscription_cr = {
                "apiVersion": "maas.opendatahub.io/v1alpha1",
                "kind": "MaaSSubscription",
                "metadata": {
                    "name": subscription_name,
                    "namespace": maas_ns,
                },
                "spec": {
                    "owner": {
                        "users": [sa_user],
                        "groups": [],
                    },
                    "modelRefs": [
                        {
                            "name": MODEL_REF,
                            "namespace": MODEL_NAMESPACE,
                            "tokenRateLimits": [{"limit": 100, "window": "1m"}],
                        },
                        {
                            "name": MODEL_REF,  # Same model ref again - guarantees duplicate
                            "namespace": MODEL_NAMESPACE,
                            "tokenRateLimits": [{"limit": 200, "window": "1m"}],
                        },
                    ],
                },
            }
            subprocess.run(
                ["oc", "apply", "-f", "-"],
                input=json.dumps(subscription_cr),
                text=True,
                check=True,
            )
    
            # Wait for subscription to reconcile before creating API key
&gt;           _wait_for_maas_subscription_phase(subscription_name, namespace=maas_ns)

test/e2e/tests/test_models_endpoint.py:818: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

name = 'e2e-dedup-subscription', expected_phase = 'Active'
namespace = 'ai-tenant-e2e-worker-w4-2af9a3', timeout = 90
require_model_statuses = False

    def _wait_for_maas_subscription_phase(name, expected_phase="Active", namespace=None, timeout=MAAS_SUBSCRIPTION_PHASE_TIMEOUT, require_model_statuses=False):
        """Wait for MaaSSubscription to reach a specific phase.
    
        Args:
            name: Name of the MaaSSubscription
            expected_phase: Phase to wait for (default: "Active")
            namespace: Namespace (defaults to _ns())
            timeout: Maximum wait time in seconds (default: 60)
            require_model_statuses: If True, also requires modelRefStatuses to be populated
                                    (default: False). Set to True for status reporting tests.
    
        Returns:
            The subscription CR dict when the expected phase is reached
    
        Raises:
            TimeoutError: If MaaSSubscription doesn't reach expected phase within timeout
        """
        namespace = namespace or _ns()
        deadline = time.time() + timeout
        log.info(f"Waiting for MaaSSubscription {name} to reach phase '{expected_phase}' (timeout: {timeout}s)...")
    
        while time.time() &lt; deadline:
            cr = _get_cr("maassubscription", name, namespace)
            if cr:
                status = cr.get("status", {})
                phase = status.get("phase")
                model_statuses = status.get("modelRefStatuses", [])
    
                if phase == expected_phase:
                    if require_model_statuses:
                        expected_count = len(cr.get("spec", {}).get("modelRefs", []))
                        if len(model_statuses) &gt;= expected_count:
                            log.info(f"MaaSSubscription {name} reached phase '{expected_phase}' with {len(model_statuses)}/{expected_count} modelRefStatuses")
                            return cr
                    else:
                        log.info(f"MaaSSubscription {name} reached phase '{expected_phase}'")
                        return cr
                log.debug(f"MaaSSubscription {name}: phase={phase}, modelRefStatuses={len(model_statuses)}")
            time.sleep(2)
    
        # Timeout - return current state for debugging
        cr = _get_cr("maassubscription", name, namespace)
        status = cr.get("status", {}) if cr else {}
&gt;       raise TimeoutError(
            f"MaaSSubscription {name} did not reach phase '{expected_phase}' within {timeout}s "
            f"(current: phase={status.get('phase')}, modelRefStatuses={len(status.get('modelRefStatuses', []))})"
        )
E       TimeoutError: MaaSSubscription e2e-dedup-subscription did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)

test/e2e/tests/test_helper.py:1334: TimeoutError</failure></testcase><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_combined_user_and_subscription@api_keys" time="92.027"><failure message="TimeoutError: MaaSSubscription e2e-combo-sub-f8f3092a did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)">self = &lt;test_api_keys.TestAPIKeyBulkOperations object at 0x7fc421f44df0&gt;
api_keys_base_url = 'https://e2e-worker-w0-6c9f0b.apps.de6489af-f880-4a63-b730-0004b3480260.prod.konfluxeaas.com/maas-api/v1/api-keys'
headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6ImNTakY1UUg2dTMxbnR3bTJrVkluSjhTZzNyaG83TmRJbWxKckVQWG9LUHcifQ.e...ghvKLGgNW-681roiUKvymiuB58tMqKB-ARgTgYhBRxYCX3pRpb6-ztqCVJcznXQ4Z8gV_XFkxauO_-Y2g', 'Content-Type': 'application/json'}
admin_headers = {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6ImNTakY1UUg2dTMxbnR3bTJrVkluSjhTZzNyaG83TmRJbWxKckVQWG9LUHcifQ.e...5gNfJ-jQWGoz6DyMZ_LEtpeyyxFCy_zDFGWahZO2mEDFDZ9rWbKMK0dRvivn0xd6HfWB8f8-KV9XRAj8g', 'Content-Type': 'application/json'}

    def test_bulk_revoke_combined_user_and_subscription(self, api_keys_base_url: str, headers: dict, admin_headers: dict):
        """Admin can revoke keys for a specific user within a specific subscription.
    
        Negative control: a second user's keys in the same subscription must remain active.
        """
        if not admin_headers:
            pytest.skip("ADMIN_OC_TOKEN not set")
    
        sub_name = f"e2e-combo-sub-{os.urandom(4).hex()}"
        ns = _ns()
        sa_name = f"e2e-combo-sa-{os.urandom(4).hex()}"
        sa2_name = f"e2e-combo-sa2-{os.urandom(4).hex()}"
    
        key_ids = []
        key_ids_user2 = []
        try:
            oc_token = _create_sa_token(sa_name, namespace=MODEL_NAMESPACE)
            sa_user = _sa_to_user(sa_name, namespace=MODEL_NAMESPACE)
            sa_headers = {"Authorization": f"Bearer {oc_token}", "Content-Type": "application/json"}
    
            oc_token2 = _create_sa_token(sa2_name, namespace=MODEL_NAMESPACE)
            sa_user2 = _sa_to_user(sa2_name, namespace=MODEL_NAMESPACE)
            sa2_headers = {"Authorization": f"Bearer {oc_token2}", "Content-Type": "application/json"}
    
            _create_test_auth_policy(f"{sub_name}-auth", MODEL_REF, users=[sa_user, sa_user2])
            _create_test_subscription(sub_name, MODEL_REF, users=[sa_user, sa_user2])
&gt;           _wait_for_maas_subscription_phase(sub_name, namespace=ns)

test/e2e/tests/test_api_keys.py:673: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

name = 'e2e-combo-sub-f8f3092a', expected_phase = 'Active'
namespace = 'ai-tenant-e2e-worker-w0-6c9f0b', timeout = 90
require_model_statuses = False

    def _wait_for_maas_subscription_phase(name, expected_phase="Active", namespace=None, timeout=MAAS_SUBSCRIPTION_PHASE_TIMEOUT, require_model_statuses=False):
        """Wait for MaaSSubscription to reach a specific phase.
    
        Args:
            name: Name of the MaaSSubscription
            expected_phase: Phase to wait for (default: "Active")
            namespace: Namespace (defaults to _ns())
            timeout: Maximum wait time in seconds (default: 60)
            require_model_statuses: If True, also requires modelRefStatuses to be populated
                                    (default: False). Set to True for status reporting tests.
    
        Returns:
            The subscription CR dict when the expected phase is reached
    
        Raises:
            TimeoutError: If MaaSSubscription doesn't reach expected phase within timeout
        """
        namespace = namespace or _ns()
        deadline = time.time() + timeout
        log.info(f"Waiting for MaaSSubscription {name} to reach phase '{expected_phase}' (timeout: {timeout}s)...")
    
        while time.time() &lt; deadline:
            cr = _get_cr("maassubscription", name, namespace)
            if cr:
                status = cr.get("status", {})
                phase = status.get("phase")
                model_statuses = status.get("modelRefStatuses", [])
    
                if phase == expected_phase:
                    if require_model_statuses:
                        expected_count = len(cr.get("spec", {}).get("modelRefs", []))
                        if len(model_statuses) &gt;= expected_count:
                            log.info(f"MaaSSubscription {name} reached phase '{expected_phase}' with {len(model_statuses)}/{expected_count} modelRefStatuses")
                            return cr
                    else:
                        log.info(f"MaaSSubscription {name} reached phase '{expected_phase}'")
                        return cr
                log.debug(f"MaaSSubscription {name}: phase={phase}, modelRefStatuses={len(model_statuses)}")
            time.sleep(2)
    
        # Timeout - return current state for debugging
        cr = _get_cr("maassubscription", name, namespace)
        status = cr.get("status", {}) if cr else {}
&gt;       raise TimeoutError(
            f"MaaSSubscription {name} did not reach phase '{expected_phase}' within {timeout}s "
            f"(current: phase={status.get('phase')}, modelRefStatuses={len(status.get('modelRefStatuses', []))})"
        )
E       TimeoutError: MaaSSubscription e2e-combo-sub-f8f3092a did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)

test/e2e/tests/test_helper.py:1334: TimeoutError</failure></testcase><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_multiple_distinct_models_in_subscription@models" time="91.987"><failure message="TimeoutError: MaaSSubscription e2e-distinct-models-subscription did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)">self = &lt;test_models_endpoint.TestModelsEndpoint object at 0x7fe0cf0fb850&gt;

    def test_multiple_distinct_models_in_subscription(self):
        """
        Test 8: Multiple distinct models should return exactly 2 entries (1 per unique ID).
    
        Uses pre-deployed models (both known to not have backend duplication issues):
        - DISTINCT_MODEL_REF (simulated-distinct) serving "test/e2e-distinct-model"
        - DISTINCT_MODEL_2_REF (simulated-distinct-2) serving "test/e2e-distinct-model-2"
    
        Creates a subscription with both models. The API should return exactly 2 entries
        (one for each distinct model ID), with no duplicates.
    
        This test validates that when backend models don't have duplication bugs, the
        API correctly returns one entry per distinct model ID.
        """
        log.info("Test 8: Multiple distinct models should return 2 entries")
    
        sa_name = "e2e-models-distinct-sa"
        sa_ns = "default"
        maas_ns = _ns()
        subscription_name = "e2e-distinct-models-subscription"
        auth_policy_name = "e2e-distinct-models-auth"
        api_key = None
    
        try:
            # Create SA
            sa_token = _create_sa_token(sa_name, namespace=sa_ns)
            sa_user = _sa_to_user(sa_name, namespace=sa_ns)
    
            # Create auth policy with both distinct models
            log.info(f"Creating auth policy with {DISTINCT_MODEL_REF} and {DISTINCT_MODEL_2_REF}")
            auth_policy_cr = {
                "apiVersion": "maas.opendatahub.io/v1alpha1",
                "kind": "MaaSAuthPolicy",
                "metadata": {
                    "name": auth_policy_name,
                    "namespace": maas_ns,
                },
                "spec": {
                    "modelRefs": [
                        {"name": DISTINCT_MODEL_REF, "namespace": MODEL_NAMESPACE},
                        {"name": DISTINCT_MODEL_2_REF, "namespace": MODEL_NAMESPACE},
                    ],
                    "subjects": {
                        "users": [sa_user],
                        "groups": [],
                    },
                },
            }
            subprocess.run(
                ["oc", "apply", "-f", "-"],
                input=json.dumps(auth_policy_cr),
                text=True,
                check=True,
            )
    
            # Create subscription with both distinct models
            log.info(f"Creating subscription with {DISTINCT_MODEL_REF} and {DISTINCT_MODEL_2_REF}")
            subscription_cr = {
                "apiVersion": "maas.opendatahub.io/v1alpha1",
                "kind": "MaaSSubscription",
                "metadata": {
                    "name": subscription_name,
                    "namespace": maas_ns,
                },
                "spec": {
                    "owner": {
                        "users": [sa_user],
                        "groups": [],
                    },
                    "modelRefs": [
                        {
                            "name": DISTINCT_MODEL_REF,
                            "namespace": MODEL_NAMESPACE,
                            "tokenRateLimits": [{"limit": 100, "window": "1m"}],
                        },
                        {
                            "name": DISTINCT_MODEL_2_REF,
                            "namespace": MODEL_NAMESPACE,
                            "tokenRateLimits": [{"limit": 100, "window": "1m"}],
                        },
                    ],
                },
            }
            subprocess.run(
                ["oc", "apply", "-f", "-"],
                input=json.dumps(subscription_cr),
                text=True,
                check=True,
            )
    
            # Wait for subscription to reconcile before creating API key
&gt;           _wait_for_maas_subscription_phase(subscription_name, namespace=maas_ns)

test/e2e/tests/test_models_endpoint.py:1176: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

name = 'e2e-distinct-models-subscription', expected_phase = 'Active'
namespace = 'ai-tenant-e2e-worker-w4-2af9a3', timeout = 90
require_model_statuses = False

    def _wait_for_maas_subscription_phase(name, expected_phase="Active", namespace=None, timeout=MAAS_SUBSCRIPTION_PHASE_TIMEOUT, require_model_statuses=False):
        """Wait for MaaSSubscription to reach a specific phase.
    
        Args:
            name: Name of the MaaSSubscription
            expected_phase: Phase to wait for (default: "Active")
            namespace: Namespace (defaults to _ns())
            timeout: Maximum wait time in seconds (default: 60)
            require_model_statuses: If True, also requires modelRefStatuses to be populated
                                    (default: False). Set to True for status reporting tests.
    
        Returns:
            The subscription CR dict when the expected phase is reached
    
        Raises:
            TimeoutError: If MaaSSubscription doesn't reach expected phase within timeout
        """
        namespace = namespace or _ns()
        deadline = time.time() + timeout
        log.info(f"Waiting for MaaSSubscription {name} to reach phase '{expected_phase}' (timeout: {timeout}s)...")
    
        while time.time() &lt; deadline:
            cr = _get_cr("maassubscription", name, namespace)
            if cr:
                status = cr.get("status", {})
                phase = status.get("phase")
                model_statuses = status.get("modelRefStatuses", [])
    
                if phase == expected_phase:
                    if require_model_statuses:
                        expected_count = len(cr.get("spec", {}).get("modelRefs", []))
                        if len(model_statuses) &gt;= expected_count:
                            log.info(f"MaaSSubscription {name} reached phase '{expected_phase}' with {len(model_statuses)}/{expected_count} modelRefStatuses")
                            return cr
                    else:
                        log.info(f"MaaSSubscription {name} reached phase '{expected_phase}'")
                        return cr
                log.debug(f"MaaSSubscription {name}: phase={phase}, modelRefStatuses={len(model_statuses)}")
            time.sleep(2)
    
        # Timeout - return current state for debugging
        cr = _get_cr("maassubscription", name, namespace)
        status = cr.get("status", {}) if cr else {}
&gt;       raise TimeoutError(
            f"MaaSSubscription {name} did not reach phase '{expected_phase}' within {timeout}s "
            f"(current: phase={status.get('phase')}, modelRefStatuses={len(status.get('modelRefStatuses', []))})"
        )
E       TimeoutError: MaaSSubscription e2e-distinct-models-subscription did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)

test/e2e/tests/test_helper.py:1334: TimeoutError</failure></testcase><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_missing_scope_returns_400@api_keys" time="0.047" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_within_expiration_limit@api_keys" time="0.036" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_at_expiration_limit@api_keys" time="0.037" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_exceeds_expiration_limit@api_keys" time="0.041" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_without_expiration@api_keys" time="0.035" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_with_short_expiration@api_keys" time="0.036" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_api_key_model_access_success@api_keys" time="0.133" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_invalid_api_key_rejected@api_keys" time="0.032" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_no_auth_header_rejected@api_keys" time="0.024" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_revoked_api_key_rejected@api_keys" time="2.130" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_api_key_chat_completions@api_keys" time="0.037" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_double_revoke_returns_404@api_keys" time="0.088" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_nonexistent_key_returns_404@api_keys" time="0.035" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_then_create_new_key_works@api_keys" time="0.158" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_individual_revoke_multiple_keys@api_keys" time="0.186" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_keys_rejected_at_gateway@api_keys" time="0.286" /><testcase classname="tests.test_api_keys.TestEphemeralKeyCleanup" name="test_cronjob_exists_and_configured@api_keys" time="0.111" /><testcase classname="tests.test_api_keys.TestEphemeralKeyCleanup" name="test_cleanup_networkpolicy_exists@api_keys" time="0.104" /><testcase classname="tests.test_api_keys.TestEphemeralKeyCleanup" name="test_create_ephemeral_key@api_keys" time="0.092" /><testcase classname="tests.test_api_keys.TestEphemeralKeyCleanup" name="test_trigger_cleanup_preserves_active_keys@api_keys" time="0.133"><skipped type="pytest.skip" message="Cannot find maas-api pod in odh-ai-gateway-infra: error: error executing jsonpath &quot;{.items[0].metadata.name}&quot;: Error executing template: array index out of bounds: index 0, length 0. Printing more information for debugging the template:&#10;&#09;template was:&#10;&#09;&#09;{.items[0].metadata.name}&#10;&#09;object given to jsonpath engine was:&#10;&#09;&#09;map[string]interface {}{&quot;apiVersion&quot;:&quot;v1&quot;, &quot;items&quot;:[]interface {}{}, &quot;kind&quot;:&quot;List&quot;, &quot;metadata&quot;:map[string]interface {}{&quot;resourceVersion&quot;:&quot;&quot;}}">/workspace/source/test/e2e/tests/test_api_keys.py:1470: Cannot find maas-api pod in odh-ai-gateway-infra: error: error executing jsonpath "{.items[0].metadata.name}": Error executing template: array index out of bounds: index 0, length 0. Printing more information for debugging the template:
	template was:
		{.items[0].metadata.name}
	object given to jsonpath engine was:
		map[string]interface {}{"apiVersion":"v1", "items":[]interface {}{}, "kind":"List", "metadata":map[string]interface {}{"resourceVersion":""}}</skipped></testcase><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_active_subscription@api_keys" time="91.811"><failure message="TimeoutError: MaaSSubscription e2e-apikey-active-sub did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)">self = &lt;test_api_keys.TestAPIKeySubscriptionPhases object at 0x7fc421f00a60&gt;

    def test_create_key_for_active_subscription(self):
        """API key creation succeeds for Active subscription."""
        ns = _ns()
        subscription_name = "e2e-apikey-active-sub"
        auth_name = "e2e-apikey-active-auth"
        sa_name = "e2e-apikey-active-sa"
    
        try:
            oc_token = _create_sa_token(sa_name, namespace=MODEL_NAMESPACE)
            sa_user = _sa_to_user(sa_name, namespace=MODEL_NAMESPACE)
    
            _create_test_auth_policy(auth_name, MODEL_REF, users=[sa_user])
            _create_test_subscription(subscription_name, MODEL_REF, users=[sa_user])
&gt;           _wait_for_maas_subscription_phase(subscription_name, namespace=ns)

test/e2e/tests/test_api_keys.py:1545: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

name = 'e2e-apikey-active-sub', expected_phase = 'Active'
namespace = 'ai-tenant-e2e-worker-w0-6c9f0b', timeout = 90
require_model_statuses = False

    def _wait_for_maas_subscription_phase(name, expected_phase="Active", namespace=None, timeout=MAAS_SUBSCRIPTION_PHASE_TIMEOUT, require_model_statuses=False):
        """Wait for MaaSSubscription to reach a specific phase.
    
        Args:
            name: Name of the MaaSSubscription
            expected_phase: Phase to wait for (default: "Active")
            namespace: Namespace (defaults to _ns())
            timeout: Maximum wait time in seconds (default: 60)
            require_model_statuses: If True, also requires modelRefStatuses to be populated
                                    (default: False). Set to True for status reporting tests.
    
        Returns:
            The subscription CR dict when the expected phase is reached
    
        Raises:
            TimeoutError: If MaaSSubscription doesn't reach expected phase within timeout
        """
        namespace = namespace or _ns()
        deadline = time.time() + timeout
        log.info(f"Waiting for MaaSSubscription {name} to reach phase '{expected_phase}' (timeout: {timeout}s)...")
    
        while time.time() &lt; deadline:
            cr = _get_cr("maassubscription", name, namespace)
            if cr:
                status = cr.get("status", {})
                phase = status.get("phase")
                model_statuses = status.get("modelRefStatuses", [])
    
                if phase == expected_phase:
                    if require_model_statuses:
                        expected_count = len(cr.get("spec", {}).get("modelRefs", []))
                        if len(model_statuses) &gt;= expected_count:
                            log.info(f"MaaSSubscription {name} reached phase '{expected_phase}' with {len(model_statuses)}/{expected_count} modelRefStatuses")
                            return cr
                    else:
                        log.info(f"MaaSSubscription {name} reached phase '{expected_phase}'")
                        return cr
                log.debug(f"MaaSSubscription {name}: phase={phase}, modelRefStatuses={len(model_statuses)}")
            time.sleep(2)
    
        # Timeout - return current state for debugging
        cr = _get_cr("maassubscription", name, namespace)
        status = cr.get("status", {}) if cr else {}
&gt;       raise TimeoutError(
            f"MaaSSubscription {name} did not reach phase '{expected_phase}' within {timeout}s "
            f"(current: phase={status.get('phase')}, modelRefStatuses={len(status.get('modelRefStatuses', []))})"
        )
E       TimeoutError: MaaSSubscription e2e-apikey-active-sub did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)

test/e2e/tests/test_helper.py:1334: TimeoutError</failure></testcase><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_tenant_admin_rbac_is_namespace_scoped@mt_lifecycle" time="56.251" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_user_token_returns_all_models@models" time="92.797"><failure message="TimeoutError: MaaSSubscription e2e-return-all-sub1 did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)">self = &lt;test_models_endpoint.TestModelsEndpoint object at 0x7fe0cf0fb2e0&gt;

    def test_user_token_returns_all_models(self):
        """
        Test: User token automatically returns models from all subscriptions.
    
        Creates a user with access to TWO subscriptions containing different models.
        Queries without X-MaaS-Subscription header and validates:
        - Returns models from ALL accessible subscriptions
        - Each model includes subscriptions array showing which subscription(s) provide access
        - Models appearing in multiple subscriptions have aggregated subscription list
        """
        log.info("Test: User token returns models from all subscriptions")
    
        sa_name = "e2e-return-all-sa"
        sa_ns = "default"
        maas_ns = _ns()
        sub1_name = "e2e-return-all-sub1"
        sub2_name = "e2e-return-all-sub2"
        auth1_name = "e2e-return-all-auth1"
        auth2_name = "e2e-return-all-auth2"
    
        try:
            # Create SA
            sa_token = _create_sa_token(sa_name, namespace=sa_ns)
            sa_user = _sa_to_user(sa_name, namespace=sa_ns)
    
            # Create subscription 1 with DISTINCT_MODEL_REF
            log.info(f"Creating subscription 1 with {DISTINCT_MODEL_REF}")
            _create_test_auth_policy(auth1_name, DISTINCT_MODEL_REF, users=[sa_user])
            _create_test_subscription(sub1_name, DISTINCT_MODEL_REF, users=[sa_user])
    
            # Create subscription 2 with DISTINCT_MODEL_2_REF
            log.info(f"Creating subscription 2 with {DISTINCT_MODEL_2_REF}")
            _create_test_auth_policy(auth2_name, DISTINCT_MODEL_2_REF, users=[sa_user])
            _create_test_subscription(sub2_name, DISTINCT_MODEL_2_REF, users=[sa_user])
    
            _wait_for_maas_auth_policy_phase(auth1_name)
            _wait_for_maas_auth_policy_phase(auth2_name)
&gt;           _wait_for_maas_subscription_phase(sub1_name)

test/e2e/tests/test_models_endpoint.py:1283: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

name = 'e2e-return-all-sub1', expected_phase = 'Active'
namespace = 'ai-tenant-e2e-worker-w4-2af9a3', timeout = 90
require_model_statuses = False

    def _wait_for_maas_subscription_phase(name, expected_phase="Active", namespace=None, timeout=MAAS_SUBSCRIPTION_PHASE_TIMEOUT, require_model_statuses=False):
        """Wait for MaaSSubscription to reach a specific phase.
    
        Args:
            name: Name of the MaaSSubscription
            expected_phase: Phase to wait for (default: "Active")
            namespace: Namespace (defaults to _ns())
            timeout: Maximum wait time in seconds (default: 60)
            require_model_statuses: If True, also requires modelRefStatuses to be populated
                                    (default: False). Set to True for status reporting tests.
    
        Returns:
            The subscription CR dict when the expected phase is reached
    
        Raises:
            TimeoutError: If MaaSSubscription doesn't reach expected phase within timeout
        """
        namespace = namespace or _ns()
        deadline = time.time() + timeout
        log.info(f"Waiting for MaaSSubscription {name} to reach phase '{expected_phase}' (timeout: {timeout}s)...")
    
        while time.time() &lt; deadline:
            cr = _get_cr("maassubscription", name, namespace)
            if cr:
                status = cr.get("status", {})
                phase = status.get("phase")
                model_statuses = status.get("modelRefStatuses", [])
    
                if phase == expected_phase:
                    if require_model_statuses:
                        expected_count = len(cr.get("spec", {}).get("modelRefs", []))
                        if len(model_statuses) &gt;= expected_count:
                            log.info(f"MaaSSubscription {name} reached phase '{expected_phase}' with {len(model_statuses)}/{expected_count} modelRefStatuses")
                            return cr
                    else:
                        log.info(f"MaaSSubscription {name} reached phase '{expected_phase}'")
                        return cr
                log.debug(f"MaaSSubscription {name}: phase={phase}, modelRefStatuses={len(model_statuses)}")
            time.sleep(2)
    
        # Timeout - return current state for debugging
        cr = _get_cr("maassubscription", name, namespace)
        status = cr.get("status", {}) if cr else {}
&gt;       raise TimeoutError(
            f"MaaSSubscription {name} did not reach phase '{expected_phase}' within {timeout}s "
            f"(current: phase={status.get('phase')}, modelRefStatuses={len(status.get('modelRefStatuses', []))})"
        )
E       TimeoutError: MaaSSubscription e2e-return-all-sub1 did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)

test/e2e/tests/test_helper.py:1334: TimeoutError</failure></testcase><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_degraded_subscription@api_keys" time="91.855"><failure message="TimeoutError: MaaSSubscription e2e-apikey-degraded-sub did not reach phase 'Degraded' within 90s (current: phase=None, modelRefStatuses=0)">self = &lt;test_api_keys.TestAPIKeySubscriptionPhases object at 0x7fc421e84280&gt;

    def test_create_key_for_degraded_subscription(self):
        """API key creation succeeds for Degraded subscription."""
        ns = _ns()
        subscription_name = "e2e-apikey-degraded-sub"
        auth_name = "e2e-apikey-degraded-auth"
        sa_name = "e2e-apikey-degraded-sa"
        missing_model = "nonexistent-model-apikey"
    
        try:
            oc_token = _create_sa_token(sa_name, namespace=MODEL_NAMESPACE)
            sa_user = _sa_to_user(sa_name, namespace=MODEL_NAMESPACE)
    
            _create_test_auth_policy(auth_name, MODEL_REF, users=[sa_user])
            # Create with valid + missing model to trigger Degraded phase
            _create_test_subscription(
                subscription_name,
                [MODEL_REF, missing_model],
                users=[sa_user]
            )
&gt;           _wait_for_maas_subscription_phase(subscription_name, expected_phase="Degraded", namespace=ns)

test/e2e/tests/test_api_keys.py:1587: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

name = 'e2e-apikey-degraded-sub', expected_phase = 'Degraded'
namespace = 'ai-tenant-e2e-worker-w0-6c9f0b', timeout = 90
require_model_statuses = False

    def _wait_for_maas_subscription_phase(name, expected_phase="Active", namespace=None, timeout=MAAS_SUBSCRIPTION_PHASE_TIMEOUT, require_model_statuses=False):
        """Wait for MaaSSubscription to reach a specific phase.
    
        Args:
            name: Name of the MaaSSubscription
            expected_phase: Phase to wait for (default: "Active")
            namespace: Namespace (defaults to _ns())
            timeout: Maximum wait time in seconds (default: 60)
            require_model_statuses: If True, also requires modelRefStatuses to be populated
                                    (default: False). Set to True for status reporting tests.
    
        Returns:
            The subscription CR dict when the expected phase is reached
    
        Raises:
            TimeoutError: If MaaSSubscription doesn't reach expected phase within timeout
        """
        namespace = namespace or _ns()
        deadline = time.time() + timeout
        log.info(f"Waiting for MaaSSubscription {name} to reach phase '{expected_phase}' (timeout: {timeout}s)...")
    
        while time.time() &lt; deadline:
            cr = _get_cr("maassubscription", name, namespace)
            if cr:
                status = cr.get("status", {})
                phase = status.get("phase")
                model_statuses = status.get("modelRefStatuses", [])
    
                if phase == expected_phase:
                    if require_model_statuses:
                        expected_count = len(cr.get("spec", {}).get("modelRefs", []))
                        if len(model_statuses) &gt;= expected_count:
                            log.info(f"MaaSSubscription {name} reached phase '{expected_phase}' with {len(model_statuses)}/{expected_count} modelRefStatuses")
                            return cr
                    else:
                        log.info(f"MaaSSubscription {name} reached phase '{expected_phase}'")
                        return cr
                log.debug(f"MaaSSubscription {name}: phase={phase}, modelRefStatuses={len(model_statuses)}")
            time.sleep(2)
    
        # Timeout - return current state for debugging
        cr = _get_cr("maassubscription", name, namespace)
        status = cr.get("status", {}) if cr else {}
&gt;       raise TimeoutError(
            f"MaaSSubscription {name} did not reach phase '{expected_phase}' within {timeout}s "
            f"(current: phase={status.get('phase')}, modelRefStatuses={len(status.get('modelRefStatuses', []))})"
        )
E       TimeoutError: MaaSSubscription e2e-apikey-degraded-sub did not reach phase 'Degraded' within 90s (current: phase=None, modelRefStatuses=0)

test/e2e/tests/test_helper.py:1334: TimeoutError</failure></testcase><testcase classname="tests.test_tenant_namespace_discovery.TestTenantWebhookValidation" name="test_maassubscription_rejected_without_tenant_config_cr@mt_lifecycle" time="6.852" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantWebhookValidation" name="test_maasauthpolicy_rejected_without_tenant_config_cr@mt_lifecycle" time="5.975" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantDiscoveryDormantMode" name="test_dormant_mode_ignores_labeled_namespace@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="Dormant-mode test mutates controller flags; set ENABLE_TENANT_DISCOVERY_DORMANT_E2E=true">/workspace/source/test/e2e/tests/test_tenant_namespace_discovery.py:355: Dormant-mode test mutates controller flags; set ENABLE_TENANT_DISCOVERY_DORMANT_E2E=true</skipped></testcase><testcase classname="tests.test_tenant_namespace_discovery.TestLegacyDefaultNamespaceStillWorks" name="test_models_as_a_service_namespace_reconciles@mt_lifecycle" time="0.532" /><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_same_tenant_access@mt_lifecycle" time="53.087"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery_isolation.py:93: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_cross_tenant_isolation@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery_isolation.py:141: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_unauthorized_access@mt_lifecycle" time="8.745" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_user_token_with_subscription_header_filters@models" time="91.971"><failure message="TimeoutError: MaaSSubscription e2e-user-token-filter-sub did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)">self = &lt;test_models_endpoint.TestModelsEndpoint object at 0x7fe0cf0fb3a0&gt;

    def test_user_token_with_subscription_header_filters(self):
        """
        Test: User token with X-MaaS-Subscription header filters to that subscription.
    
        User tokens can optionally provide X-MaaS-Subscription to filter results
        to a specific subscription (similar to API key behavior).
    
        Expected: HTTP 200 with models from only the specified subscription.
        """
        log.info("Test: User token with X-MaaS-Subscription header filters models")
    
        ns = _ns()
        auth_policy_name = "e2e-user-token-filter-auth"
        subscription_name = "e2e-user-token-filter-sub"
        sa_name = "e2e-user-token-filter-sa"
    
        try:
            # Create service account and token
            oc_token = _create_sa_token(sa_name, namespace=ns)
            sa_user = _sa_to_user(sa_name, namespace=ns)
    
            # Create test resources
            _create_test_auth_policy(auth_policy_name, MODEL_REF, users=[sa_user])
            _create_test_subscription(subscription_name, MODEL_REF, users=[sa_user])
    
            _wait_for_maas_auth_policy_phase(auth_policy_name, require_enforced=False)
&gt;           _wait_for_maas_subscription_phase(subscription_name)

test/e2e/tests/test_models_endpoint.py:1364: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

name = 'e2e-user-token-filter-sub', expected_phase = 'Active'
namespace = 'ai-tenant-e2e-worker-w4-2af9a3', timeout = 90
require_model_statuses = False

    def _wait_for_maas_subscription_phase(name, expected_phase="Active", namespace=None, timeout=MAAS_SUBSCRIPTION_PHASE_TIMEOUT, require_model_statuses=False):
        """Wait for MaaSSubscription to reach a specific phase.
    
        Args:
            name: Name of the MaaSSubscription
            expected_phase: Phase to wait for (default: "Active")
            namespace: Namespace (defaults to _ns())
            timeout: Maximum wait time in seconds (default: 60)
            require_model_statuses: If True, also requires modelRefStatuses to be populated
                                    (default: False). Set to True for status reporting tests.
    
        Returns:
            The subscription CR dict when the expected phase is reached
    
        Raises:
            TimeoutError: If MaaSSubscription doesn't reach expected phase within timeout
        """
        namespace = namespace or _ns()
        deadline = time.time() + timeout
        log.info(f"Waiting for MaaSSubscription {name} to reach phase '{expected_phase}' (timeout: {timeout}s)...")
    
        while time.time() &lt; deadline:
            cr = _get_cr("maassubscription", name, namespace)
            if cr:
                status = cr.get("status", {})
                phase = status.get("phase")
                model_statuses = status.get("modelRefStatuses", [])
    
                if phase == expected_phase:
                    if require_model_statuses:
                        expected_count = len(cr.get("spec", {}).get("modelRefs", []))
                        if len(model_statuses) &gt;= expected_count:
                            log.info(f"MaaSSubscription {name} reached phase '{expected_phase}' with {len(model_statuses)}/{expected_count} modelRefStatuses")
                            return cr
                    else:
                        log.info(f"MaaSSubscription {name} reached phase '{expected_phase}'")
                        return cr
                log.debug(f"MaaSSubscription {name}: phase={phase}, modelRefStatuses={len(model_statuses)}")
            time.sleep(2)
    
        # Timeout - return current state for debugging
        cr = _get_cr("maassubscription", name, namespace)
        status = cr.get("status", {}) if cr else {}
&gt;       raise TimeoutError(
            f"MaaSSubscription {name} did not reach phase '{expected_phase}' within {timeout}s "
            f"(current: phase={status.get('phase')}, modelRefStatuses={len(status.get('modelRefStatuses', []))})"
        )
E       TimeoutError: MaaSSubscription e2e-user-token-filter-sub did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)

test/e2e/tests/test_helper.py:1334: TimeoutError</failure></testcase><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_each_tenant_returns_own_gateway@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery_isolation.py:228: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_full_tenant_lifecycle_create_to_delete@mt_lifecycle" time="326.116"><failure message="AssertionError: maassubscription/e2e-sub-7e508e61 in ai-tenant-e2e-mt-7e508e61 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{&quot;apiVersion&quot;:&quot;maas.opendatahub.io/v1alpha1&quot;,&quot;kind&quot;:&quot;MaaSSubscription&quot;,&quot;metadata&quot;:{&quot;annotations&quot;:{},&quot;name&quot;:&quot;e2e-sub-7e508e61&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-mt-7e508e61&quot;},&quot;spec&quot;:{&quot;modelRefs&quot;:[{&quot;name&quot;:&quot;e2e-lifecycle-model-7e508e61&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-mt-7e508e61&quot;,&quot;tokenRateLimits&quot;:[{&quot;limit&quot;:100,&quot;window&quot;:&quot;1m&quot;}]}],&quot;owner&quot;:{&quot;groups&quot;:[{&quot;name&quot;:&quot;system:authenticated&quot;}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:11:23Z', 'generation': 1, 'name': 'e2e-sub-7e508e61', 'namespace': 'ai-tenant-e2e-mt-7e508e61', 'resourceVersion': '46176', 'uid': 'd54c3002-9ab1-46bc-a876-b7d32c0b3a32'}, 'spec': {'modelRefs': [{'name': 'e2e-lifecycle-model-7e508e61', 'namespace': 'ai-tenant-e2e-mt-7e508e61', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:11:23Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}">self = &lt;test_multi_tenant_integration.TestMultiTenantIntegration object at 0x7fc926ffa520&gt;

    def test_full_tenant_lifecycle_create_to_delete(self):
        """7.1: Full tenant lifecycle from create through policy/subscription reconcile to delete."""
        case = new_discovery_case()
        role_name = f"aitenant-{case['tenant_label_name']}-tenant-admin"
        try:
            bootstrap_aitenant_tenant(case)
    
            tenant = wait_for_json(TENANT_CONFIG_KIND, TENANT_CR_NAME, case["tenant_ns"], timeout=180)
            tenant_labels = tenant["metadata"].get("labels") or {}
            tenant_annotations = tenant["metadata"].get("annotations") or {}
            assert tenant_labels[LABEL_MANAGED_BY_AITENANT] == "true"
            assert tenant_labels[LABEL_TENANT_NAME] == case["tenant_label_name"]
            assert tenant_labels[LABEL_TENANT_NAMESPACE] == case["tenant_ns"]
            assert tenant_annotations[ANNOTATION_AITENANT_NAME] == case["tenant_label_name"]
            assert tenant_annotations[ANNOTATION_AITENANT_NAMESPACE] == AITENANT_NAMESPACE
            aitenant = wait_for_json(AITENANT_KIND, case["tenant_label_name"], AITENANT_NAMESPACE, timeout=180)
            assert aitenant["status"]["gatewayRef"]["name"] == case["gateway_name"]
            assert get_json_or_none("role", role_name, case["tenant_ns"]) is not None
    
            model_name = f"e2e-lifecycle-model-{case['suffix']}"
            provision_tenant_model(model_name, case["tenant_ns"], case["gateway_name"])
    
            apply_maas_auth_policy(
                case["policy_name"],
                case["tenant_ns"],
                model_ref=model_name,
                model_namespace=case["tenant_ns"],
            )
            apply_maas_subscription(
                case["subscription_name"],
                case["tenant_ns"],
                model_ref=model_name,
                model_namespace=case["tenant_ns"],
            )
            wait_for_status_phase("maasauthpolicy", case["policy_name"], case["tenant_ns"], expected_phase="Active")
&gt;           wait_for_status_phase(
                "maassubscription",
                case["subscription_name"],
                case["tenant_ns"],
                expected_phase="Active",
            )

test/e2e/tests/test_multi_tenant_integration.py:116: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:284: in wait_for_status_phase
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'maassubscription', name = 'e2e-sub-7e508e61'
namespace = 'ai-tenant-e2e-mt-7e508e61'

    def wait_for_json(
        kind: str,
        name: str,
        namespace: Optional[str] = None,
        *,
        predicate=None,
        timeout: int = 180,
        interval: int = 5,
    ) -&gt; dict:
        deadline = time.time() + timeout
        last_obj = None
        while time.time() &lt; deadline:
            obj = get_json_or_none(kind, name, namespace)
            if obj is not None:
                last_obj = obj
                if predicate is None or predicate(obj):
                    return obj
            time.sleep(interval)
&gt;       raise AssertionError(
            f"{kind}/{name} in {namespace or '&lt;cluster&gt;'} did not satisfy condition. Last object: {last_obj}"
        )
E       AssertionError: maassubscription/e2e-sub-7e508e61 in ai-tenant-e2e-mt-7e508e61 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{"apiVersion":"maas.opendatahub.io/v1alpha1","kind":"MaaSSubscription","metadata":{"annotations":{},"name":"e2e-sub-7e508e61","namespace":"ai-tenant-e2e-mt-7e508e61"},"spec":{"modelRefs":[{"name":"e2e-lifecycle-model-7e508e61","namespace":"ai-tenant-e2e-mt-7e508e61","tokenRateLimits":[{"limit":100,"window":"1m"}]}],"owner":{"groups":[{"name":"system:authenticated"}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:11:23Z', 'generation': 1, 'name': 'e2e-sub-7e508e61', 'namespace': 'ai-tenant-e2e-mt-7e508e61', 'resourceVersion': '46176', 'uid': 'd54c3002-9ab1-46bc-a876-b7d32c0b3a32'}, 'spec': {'modelRefs': [{'name': 'e2e-lifecycle-model-7e508e61', 'namespace': 'ai-tenant-e2e-mt-7e508e61', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:11:23Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}

test/e2e/tests/multitenancy_helpers.py:229: AssertionError</failure></testcase><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_failed_subscription@api_keys" time="393.113"><failure message="TimeoutError: MaaSSubscription e2e-apikey-failed-sub did not reach phase 'Failed' within 90s (current: phase=None, modelRefStatuses=0)">self = &lt;test_api_keys.TestAPIKeySubscriptionPhases object at 0x7fc421e841f0&gt;

    def test_create_key_for_failed_subscription(self):
        """API key creation is rejected for Failed subscription to prevent key spam."""
        ns = _ns()
        subscription_name = "e2e-apikey-failed-sub"
        auth_name = "e2e-apikey-failed-auth"
        sa_name = "e2e-apikey-failed-sa"
        nonexistent_model = "nonexistent-model-apikey-failed"
    
        try:
            oc_token = _create_sa_token(sa_name, namespace=MODEL_NAMESPACE)
            sa_user = _sa_to_user(sa_name, namespace=MODEL_NAMESPACE)
    
            _create_test_auth_policy(auth_name, MODEL_REF, users=[sa_user])
            # Reference only a nonexistent model so the controller naturally
            # computes Failed (all model refs invalid in deriveFinalPhase).
            _create_test_subscription(subscription_name, nonexistent_model, users=[sa_user])
&gt;           _wait_for_maas_subscription_phase(
                subscription_name, expected_phase="Failed", namespace=ns
            )

test/e2e/tests/test_api_keys.py:1626: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

name = 'e2e-apikey-failed-sub', expected_phase = 'Failed'
namespace = 'ai-tenant-e2e-worker-w0-6c9f0b', timeout = 90
require_model_statuses = False

    def _wait_for_maas_subscription_phase(name, expected_phase="Active", namespace=None, timeout=MAAS_SUBSCRIPTION_PHASE_TIMEOUT, require_model_statuses=False):
        """Wait for MaaSSubscription to reach a specific phase.
    
        Args:
            name: Name of the MaaSSubscription
            expected_phase: Phase to wait for (default: "Active")
            namespace: Namespace (defaults to _ns())
            timeout: Maximum wait time in seconds (default: 60)
            require_model_statuses: If True, also requires modelRefStatuses to be populated
                                    (default: False). Set to True for status reporting tests.
    
        Returns:
            The subscription CR dict when the expected phase is reached
    
        Raises:
            TimeoutError: If MaaSSubscription doesn't reach expected phase within timeout
        """
        namespace = namespace or _ns()
        deadline = time.time() + timeout
        log.info(f"Waiting for MaaSSubscription {name} to reach phase '{expected_phase}' (timeout: {timeout}s)...")
    
        while time.time() &lt; deadline:
            cr = _get_cr("maassubscription", name, namespace)
            if cr:
                status = cr.get("status", {})
                phase = status.get("phase")
                model_statuses = status.get("modelRefStatuses", [])
    
                if phase == expected_phase:
                    if require_model_statuses:
                        expected_count = len(cr.get("spec", {}).get("modelRefs", []))
                        if len(model_statuses) &gt;= expected_count:
                            log.info(f"MaaSSubscription {name} reached phase '{expected_phase}' with {len(model_statuses)}/{expected_count} modelRefStatuses")
                            return cr
                    else:
                        log.info(f"MaaSSubscription {name} reached phase '{expected_phase}'")
                        return cr
                log.debug(f"MaaSSubscription {name}: phase={phase}, modelRefStatuses={len(model_statuses)}")
            time.sleep(2)
    
        # Timeout - return current state for debugging
        cr = _get_cr("maassubscription", name, namespace)
        status = cr.get("status", {}) if cr else {}
&gt;       raise TimeoutError(
            f"MaaSSubscription {name} did not reach phase '{expected_phase}' within {timeout}s "
            f"(current: phase={status.get('phase')}, modelRefStatuses={len(status.get('modelRefStatuses', []))})"
        )
E       TimeoutError: MaaSSubscription e2e-apikey-failed-sub did not reach phase 'Failed' within 90s (current: phase=None, modelRefStatuses=0)

test/e2e/tests/test_helper.py:1334: TimeoutError</failure></testcase><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_response_schema_matches_openapi@models" time="0.460" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_model_metadata_preserved@models" time="0.394" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_scoped_to_subscription@models" time="393.350"><failure message="TimeoutError: MaaSSubscription e2e-api-key-scoped-sub did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)">self = &lt;test_models_endpoint.TestModelsEndpoint object at 0x7fe0cea059d0&gt;

    def test_api_key_scoped_to_subscription(self):
        """
        Test: API key returns only models from its bound subscription.
    
        API keys are scoped to a specific subscription at mint time. The gateway
        automatically injects X-MaaS-Subscription from the key's subscription.
    
        Expected: HTTP 200 with models only from the key's subscription, even if
        the user has access to multiple subscriptions.
        """
        ns = _ns()
        auth_policy_name = "e2e-api-key-scoped-auth"
        subscription_name = "e2e-api-key-scoped-sub"
        sa_name = "e2e-api-key-scoped-sa"
        api_key = None
    
        try:
            # Create service account and token
            oc_token = _create_sa_token(sa_name, namespace=ns)
            sa_user = _sa_to_user(sa_name, namespace=ns)
    
            # Create test resources
            _create_test_auth_policy(auth_policy_name, MODEL_REF, users=[sa_user])
            _create_test_subscription(subscription_name, MODEL_REF, users=[sa_user])
    
            # Wait for subscription to reconcile before creating API key
&gt;           _wait_for_maas_subscription_phase(subscription_name, namespace=ns)

test/e2e/tests/test_models_endpoint.py:1601: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

name = 'e2e-api-key-scoped-sub', expected_phase = 'Active'
namespace = 'ai-tenant-e2e-worker-w4-2af9a3', timeout = 90
require_model_statuses = False

    def _wait_for_maas_subscription_phase(name, expected_phase="Active", namespace=None, timeout=MAAS_SUBSCRIPTION_PHASE_TIMEOUT, require_model_statuses=False):
        """Wait for MaaSSubscription to reach a specific phase.
    
        Args:
            name: Name of the MaaSSubscription
            expected_phase: Phase to wait for (default: "Active")
            namespace: Namespace (defaults to _ns())
            timeout: Maximum wait time in seconds (default: 60)
            require_model_statuses: If True, also requires modelRefStatuses to be populated
                                    (default: False). Set to True for status reporting tests.
    
        Returns:
            The subscription CR dict when the expected phase is reached
    
        Raises:
            TimeoutError: If MaaSSubscription doesn't reach expected phase within timeout
        """
        namespace = namespace or _ns()
        deadline = time.time() + timeout
        log.info(f"Waiting for MaaSSubscription {name} to reach phase '{expected_phase}' (timeout: {timeout}s)...")
    
        while time.time() &lt; deadline:
            cr = _get_cr("maassubscription", name, namespace)
            if cr:
                status = cr.get("status", {})
                phase = status.get("phase")
                model_statuses = status.get("modelRefStatuses", [])
    
                if phase == expected_phase:
                    if require_model_statuses:
                        expected_count = len(cr.get("spec", {}).get("modelRefs", []))
                        if len(model_statuses) &gt;= expected_count:
                            log.info(f"MaaSSubscription {name} reached phase '{expected_phase}' with {len(model_statuses)}/{expected_count} modelRefStatuses")
                            return cr
                    else:
                        log.info(f"MaaSSubscription {name} reached phase '{expected_phase}'")
                        return cr
                log.debug(f"MaaSSubscription {name}: phase={phase}, modelRefStatuses={len(model_statuses)}")
            time.sleep(2)
    
        # Timeout - return current state for debugging
        cr = _get_cr("maassubscription", name, namespace)
        status = cr.get("status", {}) if cr else {}
&gt;       raise TimeoutError(
            f"MaaSSubscription {name} did not reach phase '{expected_phase}' within {timeout}s "
            f"(current: phase={status.get('phase')}, modelRefStatuses={len(status.get('modelRefStatuses', []))})"
        )
E       TimeoutError: MaaSSubscription e2e-api-key-scoped-sub did not reach phase 'Active' within 90s (current: phase=None, modelRefStatuses=0)

test/e2e/tests/test_helper.py:1334: TimeoutError</failure></testcase><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_default_tenant_unaffected_by_multitenancy_enablement@mt_lifecycle" time="184.779"><failure message="AssertionError: maassubscription/e2e-default-int-sub-d94bc1 in models-as-a-service did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{&quot;apiVersion&quot;:&quot;maas.opendatahub.io/v1alpha1&quot;,&quot;kind&quot;:&quot;MaaSSubscription&quot;,&quot;metadata&quot;:{&quot;annotations&quot;:{},&quot;name&quot;:&quot;e2e-default-int-sub-d94bc1&quot;,&quot;namespace&quot;:&quot;models-as-a-service&quot;},&quot;spec&quot;:{&quot;modelRefs&quot;:[{&quot;name&quot;:&quot;facebook-opt-125m-simulated&quot;,&quot;namespace&quot;:&quot;llm&quot;,&quot;tokenRateLimits&quot;:[{&quot;limit&quot;:100,&quot;window&quot;:&quot;1m&quot;}]}],&quot;owner&quot;:{&quot;groups&quot;:[{&quot;name&quot;:&quot;system:authenticated&quot;}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:15:53Z', 'generation': 1, 'name': 'e2e-default-int-sub-d94bc1', 'namespace': 'models-as-a-service', 'resourceVersion': '52038', 'uid': '90a7345b-64a1-4f0f-b17e-aecc476813ce'}, 'spec': {'modelRefs': [{'name': 'facebook-opt-125m-simulated', 'namespace': 'llm', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:15:53Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}">self = &lt;test_multi_tenant_integration.TestMultiTenantIntegration object at 0x7fc926ffadc0&gt;

    def test_default_tenant_unaffected_by_multitenancy_enablement(self):
        """7.2: Default tenant namespace still reconciles while discovery mode is enabled."""
        ns = legacy_default_namespace()
        suffix = uuid.uuid4().hex[:6]
        policy_name = f"e2e-default-int-auth-{suffix}"
        subscription_name = f"e2e-default-int-sub-{suffix}"
        try:
            apply_maas_auth_policy(policy_name, ns)
            apply_maas_subscription(subscription_name, ns)
            wait_for_status_phase("maasauthpolicy", policy_name, ns, expected_phase="Active")
&gt;           wait_for_status_phase("maassubscription", subscription_name, ns, expected_phase=("Active", "Degraded"))

test/e2e/tests/test_multi_tenant_integration.py:213: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:284: in wait_for_status_phase
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'maassubscription', name = 'e2e-default-int-sub-d94bc1'
namespace = 'models-as-a-service'

    def wait_for_json(
        kind: str,
        name: str,
        namespace: Optional[str] = None,
        *,
        predicate=None,
        timeout: int = 180,
        interval: int = 5,
    ) -&gt; dict:
        deadline = time.time() + timeout
        last_obj = None
        while time.time() &lt; deadline:
            obj = get_json_or_none(kind, name, namespace)
            if obj is not None:
                last_obj = obj
                if predicate is None or predicate(obj):
                    return obj
            time.sleep(interval)
&gt;       raise AssertionError(
            f"{kind}/{name} in {namespace or '&lt;cluster&gt;'} did not satisfy condition. Last object: {last_obj}"
        )
E       AssertionError: maassubscription/e2e-default-int-sub-d94bc1 in models-as-a-service did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{"apiVersion":"maas.opendatahub.io/v1alpha1","kind":"MaaSSubscription","metadata":{"annotations":{},"name":"e2e-default-int-sub-d94bc1","namespace":"models-as-a-service"},"spec":{"modelRefs":[{"name":"facebook-opt-125m-simulated","namespace":"llm","tokenRateLimits":[{"limit":100,"window":"1m"}]}],"owner":{"groups":[{"name":"system:authenticated"}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:15:53Z', 'generation': 1, 'name': 'e2e-default-int-sub-d94bc1', 'namespace': 'models-as-a-service', 'resourceVersion': '52038', 'uid': '90a7345b-64a1-4f0f-b17e-aecc476813ce'}, 'spec': {'modelRefs': [{'name': 'facebook-opt-125m-simulated', 'namespace': 'llm', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:15:53Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}

test/e2e/tests/multitenancy_helpers.py:229: AssertionError</failure></testcase><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_same_named_resources_across_tenants@mt_lifecycle" time="130.367"><failure message="AssertionError: maassubscription/e2e-shared-int-sub-7b5f2fa4 in ai-tenant-e2e-mt-7b5f2fa4 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{&quot;apiVersion&quot;:&quot;maas.opendatahub.io/v1alpha1&quot;,&quot;kind&quot;:&quot;MaaSSubscription&quot;,&quot;metadata&quot;:{&quot;annotations&quot;:{},&quot;name&quot;:&quot;e2e-shared-int-sub-7b5f2fa4&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-mt-7b5f2fa4&quot;},&quot;spec&quot;:{&quot;modelRefs&quot;:[{&quot;name&quot;:&quot;facebook-opt-125m-simulated&quot;,&quot;namespace&quot;:&quot;llm&quot;,&quot;tokenRateLimits&quot;:[{&quot;limit&quot;:100,&quot;window&quot;:&quot;1m&quot;}]}],&quot;owner&quot;:{&quot;groups&quot;:[{&quot;name&quot;:&quot;system:authenticated&quot;}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:18:58Z', 'generation': 1, 'name': 'e2e-shared-int-sub-7b5f2fa4', 'namespace': 'ai-tenant-e2e-mt-7b5f2fa4', 'resourceVersion': '54359', 'uid': '84f96f42-d540-44a7-a5bd-c52089326a7d'}, 'spec': {'modelRefs': [{'name': 'facebook-opt-125m-simulated', 'namespace': 'llm', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:18:58Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}">self = &lt;test_multi_tenant_integration.TestMultiTenantIntegration object at 0x7fc926e14e50&gt;

    def test_same_named_resources_across_tenants(self):
        """7.3: Same-named MaaS resources in separate tenant namespaces both contribute safely."""
        case_a = new_discovery_case(use_default_gateway=True)
        case_b = new_discovery_case(use_default_gateway=True)
        shared_policy = f"e2e-shared-int-policy-{case_a['suffix']}"
        shared_sub = f"e2e-shared-int-sub-{case_a['suffix']}"
        for case in (case_a, case_b):
            case["policy_name"] = shared_policy
            case["subscription_name"] = shared_sub
    
        try:
            for case in (case_a, case_b):
                apply_discovery_labels(case["tenant_ns"], case["tenant_label_name"])
                apply_tenant_cr(case["tenant_ns"], DEFAULT_GATEWAY_NAME)
                apply_maas_auth_policy(shared_policy, case["tenant_ns"])
                apply_maas_subscription(shared_sub, case["tenant_ns"])
                wait_for_finalizer("maasauthpolicy", shared_policy, case["tenant_ns"], FINALIZER_AUTHPOLICY)
&gt;               wait_for_finalizer("maassubscription", shared_sub, case["tenant_ns"], FINALIZER_SUBSCRIPTION)

test/e2e/tests/test_multi_tenant_integration.py:235: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:264: in wait_for_finalizer
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'maassubscription', name = 'e2e-shared-int-sub-7b5f2fa4'
namespace = 'ai-tenant-e2e-mt-7b5f2fa4'

    def wait_for_json(
        kind: str,
        name: str,
        namespace: Optional[str] = None,
        *,
        predicate=None,
        timeout: int = 180,
        interval: int = 5,
    ) -&gt; dict:
        deadline = time.time() + timeout
        last_obj = None
        while time.time() &lt; deadline:
            obj = get_json_or_none(kind, name, namespace)
            if obj is not None:
                last_obj = obj
                if predicate is None or predicate(obj):
                    return obj
            time.sleep(interval)
&gt;       raise AssertionError(
            f"{kind}/{name} in {namespace or '&lt;cluster&gt;'} did not satisfy condition. Last object: {last_obj}"
        )
E       AssertionError: maassubscription/e2e-shared-int-sub-7b5f2fa4 in ai-tenant-e2e-mt-7b5f2fa4 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{"apiVersion":"maas.opendatahub.io/v1alpha1","kind":"MaaSSubscription","metadata":{"annotations":{},"name":"e2e-shared-int-sub-7b5f2fa4","namespace":"ai-tenant-e2e-mt-7b5f2fa4"},"spec":{"modelRefs":[{"name":"facebook-opt-125m-simulated","namespace":"llm","tokenRateLimits":[{"limit":100,"window":"1m"}]}],"owner":{"groups":[{"name":"system:authenticated"}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:18:58Z', 'generation': 1, 'name': 'e2e-shared-int-sub-7b5f2fa4', 'namespace': 'ai-tenant-e2e-mt-7b5f2fa4', 'resourceVersion': '54359', 'uid': '84f96f42-d540-44a7-a5bd-c52089326a7d'}, 'spec': {'modelRefs': [{'name': 'facebook-opt-125m-simulated', 'namespace': 'llm', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:18:58Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}

test/e2e/tests/multitenancy_helpers.py:229: AssertionError</failure></testcase><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_creation_scoped_to_tenant@tenant_isolation" time="305.342"><error message="failed on setup with &quot;AssertionError: maassubscription/e2e-auth-iso-8ed1c3 in ai-tenant-e2e-shared-a-w3-aa8ef1 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{&quot;apiVersion&quot;:&quot;maas.opendatahub.io/v1alpha1&quot;,&quot;kind&quot;:&quot;MaaSSubscription&quot;,&quot;metadata&quot;:{&quot;annotations&quot;:{},&quot;name&quot;:&quot;e2e-auth-iso-8ed1c3&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-shared-a-w3-aa8ef1&quot;},&quot;spec&quot;:{&quot;modelRefs&quot;:[{&quot;name&quot;:&quot;auth-test-model-aa8ef1&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-shared-a-w3-aa8ef1&quot;,&quot;tokenRateLimits&quot;:[{&quot;limit&quot;:100,&quot;window&quot;:&quot;1m&quot;}]}],&quot;owner&quot;:{&quot;groups&quot;:[{&quot;name&quot;:&quot;system:authenticated&quot;}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:16:40Z', 'generation': 1, 'name': 'e2e-auth-iso-8ed1c3', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'resourceVersion': '52776', 'uid': 'd7315b90-fd53-4c6c-a749-f8cad1e498bd'}, 'spec': {'modelRefs': [{'name': 'auth-test-model-aa8ef1', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:16:40Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}&quot;">tenant_env = ({'base_url': 'https://e2e-shared-a-w3-aa8ef1.apps.de6489af-f880-4a63-b730-0004b3480260.prod.konfluxeaas.com/maas-api'...ared-b-w3-38d90f', 'model_name': 'auth-test-model-38d90f', 'model_namespace': 'ai-tenant-e2e-shared-b-w3-38d90f', ...})

    @pytest.fixture
    def tenant_auth_setup(tenant_env):
        tenant_a, tenant_b = tenant_env
        suffix = uuid.uuid4().hex[:6]
        policy_name = f"e2e-auth-iso-{suffix}"
        subscription_name = f"e2e-auth-iso-{suffix}"
        try:
            for tenant in tenant_env:
&gt;               make_tenant_model_accessible(
                    tenant["model_name"],
                    tenant["namespace"],
                    policy_name,
                    subscription_name,
                    gateway_name=tenant["gateway_name"],
                )

test/e2e/tests/test_tenant_auth_isolation.py:135: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:1019: in make_tenant_model_accessible
    wait_for_status_phase(
test/e2e/tests/multitenancy_helpers.py:284: in wait_for_status_phase
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'maassubscription', name = 'e2e-auth-iso-8ed1c3'
namespace = 'ai-tenant-e2e-shared-a-w3-aa8ef1'

    def wait_for_json(
        kind: str,
        name: str,
        namespace: Optional[str] = None,
        *,
        predicate=None,
        timeout: int = 180,
        interval: int = 5,
    ) -&gt; dict:
        deadline = time.time() + timeout
        last_obj = None
        while time.time() &lt; deadline:
            obj = get_json_or_none(kind, name, namespace)
            if obj is not None:
                last_obj = obj
                if predicate is None or predicate(obj):
                    return obj
            time.sleep(interval)
&gt;       raise AssertionError(
            f"{kind}/{name} in {namespace or '&lt;cluster&gt;'} did not satisfy condition. Last object: {last_obj}"
        )
E       AssertionError: maassubscription/e2e-auth-iso-8ed1c3 in ai-tenant-e2e-shared-a-w3-aa8ef1 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{"apiVersion":"maas.opendatahub.io/v1alpha1","kind":"MaaSSubscription","metadata":{"annotations":{},"name":"e2e-auth-iso-8ed1c3","namespace":"ai-tenant-e2e-shared-a-w3-aa8ef1"},"spec":{"modelRefs":[{"name":"auth-test-model-aa8ef1","namespace":"ai-tenant-e2e-shared-a-w3-aa8ef1","tokenRateLimits":[{"limit":100,"window":"1m"}]}],"owner":{"groups":[{"name":"system:authenticated"}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:16:40Z', 'generation': 1, 'name': 'e2e-auth-iso-8ed1c3', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'resourceVersion': '52776', 'uid': 'd7315b90-fd53-4c6c-a749-f8cad1e498bd'}, 'spec': {'modelRefs': [{'name': 'auth-test-model-aa8ef1', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:16:40Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}

test/e2e/tests/multitenancy_helpers.py:229: AssertionError</error></testcase><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_tenant_namespace_label_change_triggers_reconciliation@mt_lifecycle" time="37.784" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_aitenant_creates_dedicated_maas_api_infrastructure@mt_lifecycle" time="48.536" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_tenant_name_environment_variable_set@mt_lifecycle" time="0.214" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_service_routing_isolation@mt_lifecycle" time="0.429" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_httproute_tenant_attachment@mt_lifecycle" time="0.212" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_default_and_multiple_tenants_coexist@mt_lifecycle" time="83.512" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_validates_against_correct_tenant@tenant_isolation" time="185.159"><error message="failed on setup with &quot;AssertionError: maassubscription/e2e-auth-iso-909c96 in ai-tenant-e2e-shared-a-w3-aa8ef1 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{&quot;apiVersion&quot;:&quot;maas.opendatahub.io/v1alpha1&quot;,&quot;kind&quot;:&quot;MaaSSubscription&quot;,&quot;metadata&quot;:{&quot;annotations&quot;:{},&quot;name&quot;:&quot;e2e-auth-iso-909c96&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-shared-a-w3-aa8ef1&quot;},&quot;spec&quot;:{&quot;modelRefs&quot;:[{&quot;name&quot;:&quot;auth-test-model-aa8ef1&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-shared-a-w3-aa8ef1&quot;,&quot;tokenRateLimits&quot;:[{&quot;limit&quot;:100,&quot;window&quot;:&quot;1m&quot;}]}],&quot;owner&quot;:{&quot;groups&quot;:[{&quot;name&quot;:&quot;system:authenticated&quot;}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:19:45Z', 'generation': 1, 'name': 'e2e-auth-iso-909c96', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'resourceVersion': '54849', 'uid': '23287e60-572d-4747-9eb1-72da09ebb0d6'}, 'spec': {'modelRefs': [{'name': 'auth-test-model-aa8ef1', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:19:45Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}&quot;">tenant_env = ({'base_url': 'https://e2e-shared-a-w3-aa8ef1.apps.de6489af-f880-4a63-b730-0004b3480260.prod.konfluxeaas.com/maas-api'...ared-b-w3-38d90f', 'model_name': 'auth-test-model-38d90f', 'model_namespace': 'ai-tenant-e2e-shared-b-w3-38d90f', ...})

    @pytest.fixture
    def tenant_auth_setup(tenant_env):
        tenant_a, tenant_b = tenant_env
        suffix = uuid.uuid4().hex[:6]
        policy_name = f"e2e-auth-iso-{suffix}"
        subscription_name = f"e2e-auth-iso-{suffix}"
        try:
            for tenant in tenant_env:
&gt;               make_tenant_model_accessible(
                    tenant["model_name"],
                    tenant["namespace"],
                    policy_name,
                    subscription_name,
                    gateway_name=tenant["gateway_name"],
                )

test/e2e/tests/test_tenant_auth_isolation.py:135: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:1019: in make_tenant_model_accessible
    wait_for_status_phase(
test/e2e/tests/multitenancy_helpers.py:284: in wait_for_status_phase
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'maassubscription', name = 'e2e-auth-iso-909c96'
namespace = 'ai-tenant-e2e-shared-a-w3-aa8ef1'

    def wait_for_json(
        kind: str,
        name: str,
        namespace: Optional[str] = None,
        *,
        predicate=None,
        timeout: int = 180,
        interval: int = 5,
    ) -&gt; dict:
        deadline = time.time() + timeout
        last_obj = None
        while time.time() &lt; deadline:
            obj = get_json_or_none(kind, name, namespace)
            if obj is not None:
                last_obj = obj
                if predicate is None or predicate(obj):
                    return obj
            time.sleep(interval)
&gt;       raise AssertionError(
            f"{kind}/{name} in {namespace or '&lt;cluster&gt;'} did not satisfy condition. Last object: {last_obj}"
        )
E       AssertionError: maassubscription/e2e-auth-iso-909c96 in ai-tenant-e2e-shared-a-w3-aa8ef1 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{"apiVersion":"maas.opendatahub.io/v1alpha1","kind":"MaaSSubscription","metadata":{"annotations":{},"name":"e2e-auth-iso-909c96","namespace":"ai-tenant-e2e-shared-a-w3-aa8ef1"},"spec":{"modelRefs":[{"name":"auth-test-model-aa8ef1","namespace":"ai-tenant-e2e-shared-a-w3-aa8ef1","tokenRateLimits":[{"limit":100,"window":"1m"}]}],"owner":{"groups":[{"name":"system:authenticated"}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:19:45Z', 'generation': 1, 'name': 'e2e-auth-iso-909c96', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'resourceVersion': '54849', 'uid': '23287e60-572d-4747-9eb1-72da09ebb0d6'}, 'spec': {'modelRefs': [{'name': 'auth-test-model-aa8ef1', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:19:45Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}

test/e2e/tests/multitenancy_helpers.py:229: AssertionError</error></testcase><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_rejected_cross_tenant@tenant_isolation" time="185.242"><error message="failed on setup with &quot;AssertionError: maassubscription/e2e-auth-iso-38ed44 in ai-tenant-e2e-shared-a-w3-aa8ef1 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{&quot;apiVersion&quot;:&quot;maas.opendatahub.io/v1alpha1&quot;,&quot;kind&quot;:&quot;MaaSSubscription&quot;,&quot;metadata&quot;:{&quot;annotations&quot;:{},&quot;name&quot;:&quot;e2e-auth-iso-38ed44&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-shared-a-w3-aa8ef1&quot;},&quot;spec&quot;:{&quot;modelRefs&quot;:[{&quot;name&quot;:&quot;auth-test-model-aa8ef1&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-shared-a-w3-aa8ef1&quot;,&quot;tokenRateLimits&quot;:[{&quot;limit&quot;:100,&quot;window&quot;:&quot;1m&quot;}]}],&quot;owner&quot;:{&quot;groups&quot;:[{&quot;name&quot;:&quot;system:authenticated&quot;}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:22:50Z', 'generation': 1, 'name': 'e2e-auth-iso-38ed44', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'resourceVersion': '58455', 'uid': 'b614fe34-67c7-41b6-8b62-46afa561d371'}, 'spec': {'modelRefs': [{'name': 'auth-test-model-aa8ef1', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:22:50Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}&quot;">tenant_env = ({'base_url': 'https://e2e-shared-a-w3-aa8ef1.apps.de6489af-f880-4a63-b730-0004b3480260.prod.konfluxeaas.com/maas-api'...ared-b-w3-38d90f', 'model_name': 'auth-test-model-38d90f', 'model_namespace': 'ai-tenant-e2e-shared-b-w3-38d90f', ...})

    @pytest.fixture
    def tenant_auth_setup(tenant_env):
        tenant_a, tenant_b = tenant_env
        suffix = uuid.uuid4().hex[:6]
        policy_name = f"e2e-auth-iso-{suffix}"
        subscription_name = f"e2e-auth-iso-{suffix}"
        try:
            for tenant in tenant_env:
&gt;               make_tenant_model_accessible(
                    tenant["model_name"],
                    tenant["namespace"],
                    policy_name,
                    subscription_name,
                    gateway_name=tenant["gateway_name"],
                )

test/e2e/tests/test_tenant_auth_isolation.py:135: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:1019: in make_tenant_model_accessible
    wait_for_status_phase(
test/e2e/tests/multitenancy_helpers.py:284: in wait_for_status_phase
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'maassubscription', name = 'e2e-auth-iso-38ed44'
namespace = 'ai-tenant-e2e-shared-a-w3-aa8ef1'

    def wait_for_json(
        kind: str,
        name: str,
        namespace: Optional[str] = None,
        *,
        predicate=None,
        timeout: int = 180,
        interval: int = 5,
    ) -&gt; dict:
        deadline = time.time() + timeout
        last_obj = None
        while time.time() &lt; deadline:
            obj = get_json_or_none(kind, name, namespace)
            if obj is not None:
                last_obj = obj
                if predicate is None or predicate(obj):
                    return obj
            time.sleep(interval)
&gt;       raise AssertionError(
            f"{kind}/{name} in {namespace or '&lt;cluster&gt;'} did not satisfy condition. Last object: {last_obj}"
        )
E       AssertionError: maassubscription/e2e-auth-iso-38ed44 in ai-tenant-e2e-shared-a-w3-aa8ef1 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{"apiVersion":"maas.opendatahub.io/v1alpha1","kind":"MaaSSubscription","metadata":{"annotations":{},"name":"e2e-auth-iso-38ed44","namespace":"ai-tenant-e2e-shared-a-w3-aa8ef1"},"spec":{"modelRefs":[{"name":"auth-test-model-aa8ef1","namespace":"ai-tenant-e2e-shared-a-w3-aa8ef1","tokenRateLimits":[{"limit":100,"window":"1m"}]}],"owner":{"groups":[{"name":"system:authenticated"}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:22:50Z', 'generation': 1, 'name': 'e2e-auth-iso-38ed44', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'resourceVersion': '58455', 'uid': 'b614fe34-67c7-41b6-8b62-46afa561d371'}, 'spec': {'modelRefs': [{'name': 'auth-test-model-aa8ef1', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:22:50Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}

test/e2e/tests/multitenancy_helpers.py:229: AssertionError</error></testcase><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_oidc_token_validation_per_tenant@tenant_isolation" time="0.001"><skipped type="pytest.skip" message="Per-tenant OIDC tokens unavailable — set OIDC_TOKEN_URL (tenant-a) and OIDC_TOKEN_URL_TENANT_B (tenant-b), or OIDC_TOKEN_TENANT_A / OIDC_TOKEN_TENANT_B">/workspace/source/test/e2e/tests/test_tenant_auth_isolation.py:215: Per-tenant OIDC tokens unavailable — set OIDC_TOKEN_URL (tenant-a) and OIDC_TOKEN_URL_TENANT_B (tenant-b), or OIDC_TOKEN_TENANT_A / OIDC_TOKEN_TENANT_B</skipped></testcase><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_list_scoped_to_tenant@tenant_isolation" time="185.395"><error message="failed on setup with &quot;AssertionError: maassubscription/e2e-auth-iso-4a5edc in ai-tenant-e2e-shared-a-w3-aa8ef1 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{&quot;apiVersion&quot;:&quot;maas.opendatahub.io/v1alpha1&quot;,&quot;kind&quot;:&quot;MaaSSubscription&quot;,&quot;metadata&quot;:{&quot;annotations&quot;:{},&quot;name&quot;:&quot;e2e-auth-iso-4a5edc&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-shared-a-w3-aa8ef1&quot;},&quot;spec&quot;:{&quot;modelRefs&quot;:[{&quot;name&quot;:&quot;auth-test-model-aa8ef1&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-shared-a-w3-aa8ef1&quot;,&quot;tokenRateLimits&quot;:[{&quot;limit&quot;:100,&quot;window&quot;:&quot;1m&quot;}]}],&quot;owner&quot;:{&quot;groups&quot;:[{&quot;name&quot;:&quot;system:authenticated&quot;}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:25:55Z', 'generation': 1, 'name': 'e2e-auth-iso-4a5edc', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'resourceVersion': '61825', 'uid': 'c709ea69-66a6-4511-a4a4-683f7dfe047e'}, 'spec': {'modelRefs': [{'name': 'auth-test-model-aa8ef1', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:25:55Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}&quot;">tenant_env = ({'base_url': 'https://e2e-shared-a-w3-aa8ef1.apps.de6489af-f880-4a63-b730-0004b3480260.prod.konfluxeaas.com/maas-api'...ared-b-w3-38d90f', 'model_name': 'auth-test-model-38d90f', 'model_namespace': 'ai-tenant-e2e-shared-b-w3-38d90f', ...})

    @pytest.fixture
    def tenant_auth_setup(tenant_env):
        tenant_a, tenant_b = tenant_env
        suffix = uuid.uuid4().hex[:6]
        policy_name = f"e2e-auth-iso-{suffix}"
        subscription_name = f"e2e-auth-iso-{suffix}"
        try:
            for tenant in tenant_env:
&gt;               make_tenant_model_accessible(
                    tenant["model_name"],
                    tenant["namespace"],
                    policy_name,
                    subscription_name,
                    gateway_name=tenant["gateway_name"],
                )

test/e2e/tests/test_tenant_auth_isolation.py:135: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:1019: in make_tenant_model_accessible
    wait_for_status_phase(
test/e2e/tests/multitenancy_helpers.py:284: in wait_for_status_phase
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'maassubscription', name = 'e2e-auth-iso-4a5edc'
namespace = 'ai-tenant-e2e-shared-a-w3-aa8ef1'

    def wait_for_json(
        kind: str,
        name: str,
        namespace: Optional[str] = None,
        *,
        predicate=None,
        timeout: int = 180,
        interval: int = 5,
    ) -&gt; dict:
        deadline = time.time() + timeout
        last_obj = None
        while time.time() &lt; deadline:
            obj = get_json_or_none(kind, name, namespace)
            if obj is not None:
                last_obj = obj
                if predicate is None or predicate(obj):
                    return obj
            time.sleep(interval)
&gt;       raise AssertionError(
            f"{kind}/{name} in {namespace or '&lt;cluster&gt;'} did not satisfy condition. Last object: {last_obj}"
        )
E       AssertionError: maassubscription/e2e-auth-iso-4a5edc in ai-tenant-e2e-shared-a-w3-aa8ef1 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{"apiVersion":"maas.opendatahub.io/v1alpha1","kind":"MaaSSubscription","metadata":{"annotations":{},"name":"e2e-auth-iso-4a5edc","namespace":"ai-tenant-e2e-shared-a-w3-aa8ef1"},"spec":{"modelRefs":[{"name":"auth-test-model-aa8ef1","namespace":"ai-tenant-e2e-shared-a-w3-aa8ef1","tokenRateLimits":[{"limit":100,"window":"1m"}]}],"owner":{"groups":[{"name":"system:authenticated"}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:25:55Z', 'generation': 1, 'name': 'e2e-auth-iso-4a5edc', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'resourceVersion': '61825', 'uid': 'c709ea69-66a6-4511-a4a4-683f7dfe047e'}, 'spec': {'modelRefs': [{'name': 'auth-test-model-aa8ef1', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:25:55Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}

test/e2e/tests/multitenancy_helpers.py:229: AssertionError</error></testcase><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_metadata_not_leaked_cross_tenant@tenant_isolation" time="222.950"><error message="failed on setup with &quot;AssertionError: maassubscription/e2e-auth-iso-18f025 in ai-tenant-e2e-shared-a-w3-aa8ef1 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{&quot;apiVersion&quot;:&quot;maas.opendatahub.io/v1alpha1&quot;,&quot;kind&quot;:&quot;MaaSSubscription&quot;,&quot;metadata&quot;:{&quot;annotations&quot;:{},&quot;name&quot;:&quot;e2e-auth-iso-18f025&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-shared-a-w3-aa8ef1&quot;},&quot;spec&quot;:{&quot;modelRefs&quot;:[{&quot;name&quot;:&quot;auth-test-model-aa8ef1&quot;,&quot;namespace&quot;:&quot;ai-tenant-e2e-shared-a-w3-aa8ef1&quot;,&quot;tokenRateLimits&quot;:[{&quot;limit&quot;:100,&quot;window&quot;:&quot;1m&quot;}]}],&quot;owner&quot;:{&quot;groups&quot;:[{&quot;name&quot;:&quot;system:authenticated&quot;}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:29:01Z', 'generation': 1, 'name': 'e2e-auth-iso-18f025', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'resourceVersion': '63747', 'uid': '9ea338fd-ad57-4241-b7e5-d44959daa12e'}, 'spec': {'modelRefs': [{'name': 'auth-test-model-aa8ef1', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:29:01Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}&quot;">tenant_env = ({'base_url': 'https://e2e-shared-a-w3-aa8ef1.apps.de6489af-f880-4a63-b730-0004b3480260.prod.konfluxeaas.com/maas-api'...ared-b-w3-38d90f', 'model_name': 'auth-test-model-38d90f', 'model_namespace': 'ai-tenant-e2e-shared-b-w3-38d90f', ...})

    @pytest.fixture
    def tenant_auth_setup(tenant_env):
        tenant_a, tenant_b = tenant_env
        suffix = uuid.uuid4().hex[:6]
        policy_name = f"e2e-auth-iso-{suffix}"
        subscription_name = f"e2e-auth-iso-{suffix}"
        try:
            for tenant in tenant_env:
&gt;               make_tenant_model_accessible(
                    tenant["model_name"],
                    tenant["namespace"],
                    policy_name,
                    subscription_name,
                    gateway_name=tenant["gateway_name"],
                )

test/e2e/tests/test_tenant_auth_isolation.py:135: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:1019: in make_tenant_model_accessible
    wait_for_status_phase(
test/e2e/tests/multitenancy_helpers.py:284: in wait_for_status_phase
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'maassubscription', name = 'e2e-auth-iso-18f025'
namespace = 'ai-tenant-e2e-shared-a-w3-aa8ef1'

    def wait_for_json(
        kind: str,
        name: str,
        namespace: Optional[str] = None,
        *,
        predicate=None,
        timeout: int = 180,
        interval: int = 5,
    ) -&gt; dict:
        deadline = time.time() + timeout
        last_obj = None
        while time.time() &lt; deadline:
            obj = get_json_or_none(kind, name, namespace)
            if obj is not None:
                last_obj = obj
                if predicate is None or predicate(obj):
                    return obj
            time.sleep(interval)
&gt;       raise AssertionError(
            f"{kind}/{name} in {namespace or '&lt;cluster&gt;'} did not satisfy condition. Last object: {last_obj}"
        )
E       AssertionError: maassubscription/e2e-auth-iso-18f025 in ai-tenant-e2e-shared-a-w3-aa8ef1 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{"apiVersion":"maas.opendatahub.io/v1alpha1","kind":"MaaSSubscription","metadata":{"annotations":{},"name":"e2e-auth-iso-18f025","namespace":"ai-tenant-e2e-shared-a-w3-aa8ef1"},"spec":{"modelRefs":[{"name":"auth-test-model-aa8ef1","namespace":"ai-tenant-e2e-shared-a-w3-aa8ef1","tokenRateLimits":[{"limit":100,"window":"1m"}]}],"owner":{"groups":[{"name":"system:authenticated"}]}}}\n'}, 'creationTimestamp': '2026-09-15T13:29:01Z', 'generation': 1, 'name': 'e2e-auth-iso-18f025', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'resourceVersion': '63747', 'uid': '9ea338fd-ad57-4241-b7e5-d44959daa12e'}, 'spec': {'modelRefs': [{'name': 'auth-test-model-aa8ef1', 'namespace': 'ai-tenant-e2e-shared-a-w3-aa8ef1', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-09-15T13:29:01Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}]}}

test/e2e/tests/multitenancy_helpers.py:229: AssertionError</error></testcase></testsuite></testsuites>