<?xml version="1.0" encoding="utf-8"?><testsuites name="pytest tests"><testsuite name="pytest" errors="10" failures="3" skipped="43" tests="217" time="1039.792" timestamp="2026-09-14T13:12:17.037434+00:00" hostname="maas-group-test-ltk8k-e2e-maas-openshift-pod"><testcase classname="tests.test_smoke" name="test_healthz_or_404@readonly" time="0.030" /><testcase classname="tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_subscription_namespace_visible_to_api@security" time="0.002"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:214: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_another_namespace_not_visible_to_api@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:247: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_maas_subscription_namespace@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:287: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_another_namespace@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:324: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestModelRef" name="test_auth_policy_model_ref@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:382: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestModelRef" name="test_subscription_model_ref@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:456: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_negative_security.TestAPIKeyManagementIsolation" name="test_api_key_cannot_mint_another_api_key@security" time="0.229" /><testcase classname="tests.test_smoke" name="test_tokens_endpoint_replaced_by_api_keys@readonly" time="0.034" /><testcase classname="tests.test_smoke" name="test_models_catalog@readonly" time="0.043" /><testcase classname="tests.test_smoke" name="test_chat_completions_gateway_alive@readonly" time="0.075" /><testcase classname="tests.test_smoke" name="test_legacy_completions_optionally@readonly" time="0.041" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_forged_identity_headers_rejected_on_key_mint[username-only]@security" time="0.315" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_default_aitenant_bootstraps_maas_tenant_config_without_gateway_mutation@mt_lifecycle" time="1.859" /><testcase classname="tests.test_tenant.TestTenantLifecycle" name="test_tenant_ready_and_phase_healthy@readonly" time="0.399" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_forged_identity_headers_rejected_on_key_mint[group-only]@security" time="0.353" /><testcase classname="tests.test_tenant.TestTenantContract" name="test_status_has_phase_and_conditions@readonly" time="0.138" /><testcase classname="tests.test_tenant.TestTenantContract" name="test_spec_is_well_formed@readonly" time="0.134" /><testcase classname="tests.test_tenant.TestTenantContract" name="test_conditions_use_kubernetes_metav1_shape@readonly" time="0.128" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_injected_identity_headers_rejected_on_inference@security" time="0.205" /><testcase classname="tests.test_tenant.TestTenantNoFalseOwnership" name="test_maas_user_crs_not_owned_by_tenant@readonly" time="0.369" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_duplicate_subscription_headers_ignored@security" time="0.245" /><testcase classname="tests.test_negative_security.TestExpiredKeyRejection" name="test_expired_key_rejected_at_gateway@security" time="5.076" /><testcase classname="tests.test_config_tenant.TestConfigAnchorPresence" name="test_cluster_config_default_exists@readonly" time="0.420" /><testcase classname="tests.test_config_tenant.TestConfigAnchorPresence" name="test_cluster_config_not_terminating@readonly" time="0.167" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_rejected_outside_ai_tenants_namespace@mt_lifecycle" time="8.809" /><testcase classname="tests.test_config_tenant.TestConfigTenantOwnership" name="test_default_aitenant_lists_config_owner_reference@readonly" time="0.137" /><testcase classname="tests.test_config_tenant.TestConfigTenantOwnership" name="test_tenant_config_lists_config_owner_reference@readonly" time="0.129" /><testcase classname="tests.test_config_tenant.TestConfigTenantOwnership" name="test_maas_controller_deployment_does_not_list_config_owner_reference@readonly" time="0.150" /><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_requires_auth@readonly" time="5.891" /><testcase classname="tests.test_external_models.TestExternalModelDiscovery" name="test_maasmodelref_created@external" time="5.787" /><testcase classname="tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_httproute@external" time="0.120" /><testcase classname="tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_backend_service@external" time="0.117" /><testcase classname="tests.test_external_models.TestExternalModelAuth" name="test_invalid_key_returns_401@external" time="0.034" /><testcase classname="tests.test_external_models.TestExternalModelAuth" name="test_no_key_returns_401@external" time="0.028" /><testcase classname="tests.test_external_models.TestExternalModelEgress" name="test_request_forwarded_returns_200@external" time="0.145" /><testcase classname="tests.test_external_models.TestExternalModelCleanup" name="test_delete_removes_httproute@external" time="12.729" /><testcase classname="tests.test_negative_security.TestCrossModelAccess" name="test_key_cannot_access_model_outside_subscription@security" time="2.402" /><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_with_invalid_token@readonly" time="2.017" /><testcase classname="tests.test_negative_security.TestMissingModelRef" name="test_subscription_with_nonexistent_model_ref@security" time="1.156" /><testcase classname="tests.test_negative_security.TestMissingModelRef" name="test_authpolicy_with_nonexistent_model_ref@security" time="3.055" /><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_authenticated@readonly" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery.py:79: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_gateway_matches_deployment@readonly" time="0.000"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery.py:155: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_not_exposed_through_gateway@readonly" time="0.029" /><testcase classname="tests.test_tenant_auto_resolve.TestTenantAutoResolve" name="test_auto_resolve_populates_resolved_tenant_ref@tenant_auto_resolve" time="203.749" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_create_bootstrap_resources@mt_lifecycle" time="38.166" /><testcase classname="tests.test_negative_security.TestHeaderAbuse" name="test_special_characters_in_subscription_header@security" time="0.412" /><testcase classname="tests.test_negative_security.TestWebhookValidation" name="test_subscription_rejected_in_unlabeled_namespace@security" time="8.631" /><testcase classname="tests.test_external_models.TestExternalModelPathRouting" name="test_wrong_path_returns_not_found@external" time="0.048" /><testcase classname="tests.test_external_models.TestLegacyExternalModelMigration" name="test_migration_sets_legacy_status_and_removes_networking@external" time="3.954" /><testcase classname="tests.test_negative_security.TestWebhookValidation" name="test_authpolicy_rejected_in_unlabeled_namespace@security" time="7.858" /><testcase classname="tests.test_external_models.TestExternalModelBodyRouting" name="test_correct_model_in_body_succeeds@external" time="0.306" /><testcase classname="tests.test_external_models.TestExternalModelBodyRouting" name="test_wrong_model_in_body_does_not_error@external" time="0.236" /><testcase classname="tests.test_external_models.TestExternalModelBodyRouting" name="test_missing_model_in_body_does_not_error@external" time="1.390" /><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_oidc_token_can_create_api_key@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:252: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_invalid_oidc_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:263: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_empty_bearer_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:277: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_no_auth_header_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:290: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_tampered_expired_oidc_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:303: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_real_expired_oidc_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:335: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenClaims" name="test_token_contains_groups_claim@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:379: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenClaims" name="test_token_contains_preferred_username@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:395: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenClaims" name="test_different_users_have_different_groups@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:405: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiUser" name="test_bob_sre_can_mint_api_key@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:428: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiUser" name="test_wrong_password_gets_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:436: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiUser" name="test_nonexistent_user_gets_rejected@external" time="0.002"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:441: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCModelAccess" name="test_minted_api_key_can_list_models_and_infer@external" time="0.001"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:454: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCModelAccess" name="test_revoked_api_key_cannot_access_models@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:501: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCModelAccess" name="test_oidc_user_without_group_access_gets_empty_list@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:537: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiTenant" name="test_tenant_b_token_rejected_by_maas@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:602: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiTenant" name="test_tenant_a_users_are_isolated@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:633: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCAPIKeyLifecycle" name="test_create_and_revoke_api_key@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:659: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCAPIKeyLifecycle" name="test_api_key_owner_matches_oidc_username@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:690: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_username_header_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:750: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_group_header_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:786: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_subscription_header_ignored@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:824: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_username_on_oidc_token_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:872: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCClientBinding" name="test_wrong_oauth_client_token_is_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:961: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCGroupSafety" name="test_unsafe_group_name_is_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1013: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCGroupSafety" name="test_mixed_safe_and_unsafe_groups_is_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1049: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCDirectModelAccess" name="test_oidc_token_can_list_models_directly@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1103: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCAlertingInfra" name="test_authorino_prometheusrule_exists@external" time="0.001"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1142: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_internal_endpoint_not_routable[subscriptions-select]@security" time="0.269" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_internal_endpoint_not_routable[api-keys-cleanup]@security" time="0.193" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_internal_endpoint_not_routable[api-keys-validate]@security" time="0.194" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_health_endpoint_accessible@security" time="0.044" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_v1_models_via_maas_api_prefix@security" time="0.306" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_migrates_and_removes_legacy_tenant@mt_lifecycle" time="35.730" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_delete_cleans_maas_resources_and_preserves_user_objects@mt_lifecycle" time="37.340" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_derives_non_default_tenant_namespace@mt_lifecycle" time="35.668" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_labeled_tenant_namespace_is_discovered@mt_lifecycle" time="8.859" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_label_removal_stops_reconciliation@mt_lifecycle" time="32.813" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_unlabeled_namespace_ignored@mt_lifecycle" time="23.535" /><testcase classname="tests.test_tenant_auto_resolve.TestTenantAutoResolve" name="test_explicit_tenant_ref_preserved@tenant_auto_resolve" time="180.540" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_dynamic_discovery_after_label_added@mt_lifecycle" time="18.432" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_per_tenant_oidc_configuration@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="OIDC_ISSUER_URL not set; per-tenant OIDC E2E requires external OIDC deploy">/workspace/source/test/e2e/tests/test_tenant_namespace_discovery.py:189: OIDC_ISSUER_URL not set; per-tenant OIDC E2E requires external OIDC deploy</skipped></testcase><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_namespace_qualified_collision_prevention@mt_lifecycle" time="16.462" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_tenant_admin_rbac_is_namespace_scoped@mt_lifecycle" time="65.107" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantWebhookValidation" name="test_maassubscription_rejected_without_tenant_config_cr@mt_lifecycle" time="6.862" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantWebhookValidation" name="test_maasauthpolicy_rejected_without_tenant_config_cr@mt_lifecycle" time="7.673" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantDiscoveryDormantMode" name="test_dormant_mode_ignores_labeled_namespace@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="Dormant-mode test mutates controller flags; set ENABLE_TENANT_DISCOVERY_DORMANT_E2E=true">/workspace/source/test/e2e/tests/test_tenant_namespace_discovery.py:355: Dormant-mode test mutates controller flags; set ENABLE_TENANT_DISCOVERY_DORMANT_E2E=true</skipped></testcase><testcase classname="tests.test_tenant_namespace_discovery.TestLegacyDefaultNamespaceStillWorks" name="test_models_as_a_service_namespace_reconciles@mt_lifecycle" time="0.600" /><testcase classname="tests.test_api_keys.TestAPIKeyCRUD" name="test_create_api_key@api_keys" time="339.737" /><testcase classname="tests.test_api_keys.TestAPIKeyCRUD" name="test_list_api_keys@api_keys" time="0.150" /><testcase classname="tests.test_api_keys.TestAPIKeyCRUD" name="test_revoke_api_key@api_keys" time="0.109" /><testcase classname="tests.test_api_keys.TestAPIKeyAuthorization" name="test_admin_manage_other_users_keys@api_keys" time="0.619" /><testcase classname="tests.test_api_keys.TestAPIKeyAuthorization" name="test_non_admin_cannot_access_other_users_keys@api_keys" time="0.126" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_own_keys@api_keys" time="0.266" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_other_user_forbidden@api_keys" time="0.033" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_admin_can_revoke_any_user@api_keys" time="0.116" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_by_subscription@api_keys" time="1.862" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_by_subscription_forbidden_for_non_admin@api_keys" time="0.037" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_dry_run@api_keys" time="0.197" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_dry_run_by_subscription@api_keys" time="3.800" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_combined_user_and_subscription@api_keys" time="2.089" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_missing_scope_returns_400@api_keys" time="0.035" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_within_expiration_limit@api_keys" time="0.032" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_at_expiration_limit@api_keys" time="0.033" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_exceeds_expiration_limit@api_keys" time="0.031" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_without_expiration@api_keys" time="0.036" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_with_short_expiration@api_keys" time="0.037" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_api_key_model_access_success@api_keys" time="0.127" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_invalid_api_key_rejected@api_keys" time="0.028" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_no_auth_header_rejected@api_keys" time="0.028" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_revoked_api_key_rejected@api_keys" time="2.157" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_api_key_chat_completions@api_keys" time="0.041" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_double_revoke_returns_404@api_keys" time="0.102" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_nonexistent_key_returns_404@api_keys" time="0.033" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_then_create_new_key_works@api_keys" time="0.175" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_individual_revoke_multiple_keys@api_keys" time="0.197" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_keys_rejected_at_gateway@api_keys" time="0.320" /><testcase classname="tests.test_api_keys.TestEphemeralKeyCleanup" name="test_cronjob_exists_and_configured@api_keys" time="0.117" /><testcase classname="tests.test_api_keys.TestEphemeralKeyCleanup" name="test_cleanup_networkpolicy_exists@api_keys" time="0.118" /><testcase classname="tests.test_api_keys.TestEphemeralKeyCleanup" name="test_create_ephemeral_key@api_keys" time="0.107" /><testcase classname="tests.test_api_keys.TestEphemeralKeyCleanup" name="test_trigger_cleanup_preserves_active_keys@api_keys" time="0.151"><skipped type="pytest.skip" message="Cannot find maas-api pod in odh-ai-gateway-infra: error: error executing jsonpath &quot;{.items[0].metadata.name}&quot;: Error executing template: array index out of bounds: index 0, length 0. Printing more information for debugging the template:&#10;&#09;template was:&#10;&#09;&#09;{.items[0].metadata.name}&#10;&#09;object given to jsonpath engine was:&#10;&#09;&#09;map[string]interface {}{&quot;apiVersion&quot;:&quot;v1&quot;, &quot;items&quot;:[]interface {}{}, &quot;kind&quot;:&quot;List&quot;, &quot;metadata&quot;:map[string]interface {}{&quot;resourceVersion&quot;:&quot;&quot;}}">/workspace/source/test/e2e/tests/test_api_keys.py:1470: Cannot find maas-api pod in odh-ai-gateway-infra: error: error executing jsonpath "{.items[0].metadata.name}": Error executing template: array index out of bounds: index 0, length 0. Printing more information for debugging the template:
	template was:
		{.items[0].metadata.name}
	object given to jsonpath engine was:
		map[string]interface {}{"apiVersion":"v1", "items":[]interface {}{}, "kind":"List", "metadata":map[string]interface {}{"resourceVersion":""}}</skipped></testcase><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_active_subscription@api_keys" time="1.588" /><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_degraded_subscription@api_keys" time="1.593" /><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_failed_subscription@api_keys" time="1.564" /><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionFilter" name="test_search_filters_by_subscription@api_keys" time="2.468" /><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionFilter" name="test_search_without_subscription_returns_all@api_keys" time="0.299" /><testcase classname="tests.test_api_keys.TestAPIKeyLabels" name="test_create_api_key_with_labels@api_keys" time="0.069" /><testcase classname="tests.test_api_keys.TestAPIKeyLabels" name="test_search_api_keys_by_labels@api_keys" time="0.194" /><testcase classname="tests.test_api_keys.TestAPIKeyLabels" name="test_labels_validation_errors@api_keys" time="0.114" /><testcase classname="tests.test_api_keys.TestAPIKeyLabels" name="test_backward_compatibility_no_labels@api_keys" time="0.304" /><testcase classname="tests.test_subscription.TestAuthEnforcement" name="test_authorized_user_gets_200@api_keys" time="0.081" /><testcase classname="tests.test_subscription.TestAuthEnforcement" name="test_no_auth_gets_401@api_keys" time="0.026" /><testcase classname="tests.test_subscription.TestAuthEnforcement" name="test_invalid_token_gets_403@api_keys" time="0.098" /><testcase classname="tests.test_subscription.TestAuthEnforcement" name="test_wrong_group_gets_403@api_keys" time="0.031" /><testcase classname="tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_uses_highest_priority_subscription@api_keys" time="0.340" /><testcase classname="tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_with_explicit_simulator_subscription@api_keys" time="0.067" /><testcase classname="tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_nonexistent_subscription_errors@api_keys" time="0.260" /><testcase classname="tests.test_subscription.TestSubscriptionEnforcement" name="test_subscribed_user_gets_200@api_keys" time="0.168" /><testcase classname="tests.test_subscription.TestSubscriptionEnforcement" name="test_auth_pass_no_subscription_gets_403@api_keys" time="0.664" /><testcase classname="tests.test_subscription.TestMultipleAuthPoliciesPerModel" name="test_two_auth_policies_or_logic@api_keys" time="1.126" /><testcase classname="tests.test_subscription.TestOrderingEdgeCases" name="test_subscription_before_auth_policy@api_keys" time="1.996" /><testcase classname="tests.test_subscription.TestManagedAnnotation" name="test_authpolicy_managed_false_prevents_update@api_keys" time="0.233"><skipped type="pytest.skip" message="gateway-only mode: per-model AuthPolicy is not created">/workspace/source/test/e2e/tests/test_subscription.py:1181: gateway-only mode: per-model AuthPolicy is not created</skipped></testcase><testcase classname="tests.test_subscription.TestManagedAnnotation" name="test_trlp_managed_false_prevents_update@api_keys" time="2.126" /><testcase classname="tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_both_access_and_subscription_gets_200@api_keys" time="1.966" /><testcase classname="tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_subscription_but_no_access_gets_403@api_keys" time="2.089" /><testcase classname="tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_multiple_subscriptions_separate_keys_gets_200@api_keys" time="2.130" /><testcase classname="tests.test_tenant_model_inference.TestTenantModelInference" name="test_model_routes_through_tenant_gateway@tenant_isolation" time="373.838" /><testcase classname="tests.test_tenant_model_inference.TestTenantModelInference" name="test_inference_succeeds_through_tenant_gateway@tenant_isolation" time="8.304" /><testcase classname="tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_mint_api_key_denied_for_inaccessible_subscription@api_keys" time="2.434" /><testcase classname="tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_access_gets_200@api_keys" time="1.575" /><testcase classname="tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_subscription_but_no_auth_gets_403@api_keys" time="1.661" /><testcase classname="tests.test_tenant_model_inference.TestTenantModelInference" name="test_tenant_isolation_cross_gateway_blocked@tenant_isolation" time="0.356" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_correct_model_in_body_succeeds@tenant_isolation" time="8.238" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_wrong_model_in_body_rejected@tenant_isolation" time="8.219" /><testcase classname="tests.test_tenant_auto_resolve.TestTenantAutoResolve" name="test_no_matching_tenant_enters_failed@tenant_auto_resolve" time="128.823" /><testcase classname="tests.test_model_identity_conflict.TestModelIdentityConflictDetection" name="test_colliding_model_names_flagged_then_resolved@models" time="660.397" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_missing_model_in_body_rejected@tenant_isolation" time="8.232" /><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_same_tenant_access@mt_lifecycle" time="68.850"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery_isolation.py:93: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_cross_tenant_isolation@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery_isolation.py:141: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_unauthorized_access@mt_lifecycle" time="7.953" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_each_tenant_routes_to_own_model@tenant_isolation" time="152.943" /><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_each_tenant_returns_own_gateway@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery_isolation.py:228: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_full_tenant_lifecycle_create_to_delete@mt_lifecycle" time="240.319" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_subscription_active_status_with_valid_model@api_keys" time="249.401" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_subscription_failed_status_with_missing_model@api_keys" time="0.905" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_authpolicy_active_status_with_valid_model@api_keys" time="1.027" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_authpolicy_failed_status_with_missing_model@api_keys" time="0.937" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_subscription_degraded_status_with_partial_models@api_keys" time="3.418" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_authpolicy_degraded_status_with_partial_models@api_keys" time="0.914" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_subscription_status_transitions_on_model_deletion@api_keys" time="32.052" /><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_default_tenant_unaffected_by_multitenancy_enablement@mt_lifecycle" time="1.043" /><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_same_named_resources_across_tenants@mt_lifecycle" time="40.639" /><testcase classname="tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_degraded_healthy_model_allows_inference@api_keys" time="3.306" /><testcase classname="tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_failed_subscription_blocks_inference@api_keys" time="1.618" /><testcase classname="tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_models_endpoint_with_degraded_subscription_api_key@api_keys" time="1.430" /><testcase classname="tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_models_endpoint_with_degraded_subscription_kube_token@api_keys" time="1.347" /><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptions" name="test_returns_accessible_subscriptions@api_keys" time="5.272" /><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptions" name="test_unauthenticated_returns_401@api_keys" time="0.031" /><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptions" name="test_subscription_includes_model_refs@api_keys" time="11.211" /><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptions" name="test_model_ref_display_name_and_description_enriched@api_keys" time="133.669"><failure message="TimeoutError: MaaSSubscription e2e-enrichment-sub did not reach phase 'Active' within 90s (current: phase=Degraded, modelRefStatuses=1)">self = &lt;test_subscription_list_endpoints.TestListSubscriptions object at 0x7fcad8b02730&gt;

    def test_model_ref_display_name_and_description_enriched(self):
        """Model refs include display_name and description from MaaSModelRef annotations."""
        sa_name = "e2e-enrichment-sa"
        sa_ns = "default"
        maas_ns = _ns()
        model_ref_name = "e2e-enrichment-model-ref"
        model_ns = MODEL_NAMESPACE
        subscription_name = "e2e-enrichment-sub"
        auth_policy_name = "e2e-enrichment-auth"
        expected_display_name = "E2E Enrichment Test Model"
        expected_description = "Model created by e2e test to verify display_name/description enrichment"
    
        try:
            sa_token = _create_sa_token(sa_name, namespace=sa_ns)
            sa_user = _sa_to_user(sa_name, namespace=sa_ns)
    
            # Create a MaaSModelRef with display-name and description annotations.
            # Points to the existing e2e-distinct-simulated LLMIS so the controller
            # can reconcile the subscription to Active.
            _apply_cr({
                "apiVersion": "maas.opendatahub.io/v1alpha1",
                "kind": "MaaSModelRef",
                "metadata": {
                    "name": model_ref_name,
                    "namespace": model_ns,
                    "annotations": {
                        "openshift.io/display-name": expected_display_name,
                        "openshift.io/description": expected_description,
                    },
                },
                "spec": {
                    "modelRef": {
                        "kind": "LLMInferenceService",
                        "name": DISTINCT_MODEL_REF,
                    }
                },
            })
    
            _create_test_subscription(
                subscription_name,
                model_ref_name,
                users=[sa_user],
            )
    
            _create_test_auth_policy(
                auth_policy_name,
                model_ref_name,
                users=[sa_user],
            )
    
            api_key = _create_api_key(sa_token, name=f"{sa_name}-key")
    
&gt;           _wait_for_maas_subscription_phase(subscription_name, namespace=maas_ns)

test/e2e/tests/test_subscription_list_endpoints.py:316: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

name = 'e2e-enrichment-sub', expected_phase = 'Active'
namespace = 'ai-tenant-e2e-worker-w0-aea349', timeout = 90
require_model_statuses = False

    def _wait_for_maas_subscription_phase(name, expected_phase="Active", namespace=None, timeout=MAAS_SUBSCRIPTION_PHASE_TIMEOUT, require_model_statuses=False):
        """Wait for MaaSSubscription to reach a specific phase.
    
        Args:
            name: Name of the MaaSSubscription
            expected_phase: Phase to wait for (default: "Active")
            namespace: Namespace (defaults to _ns())
            timeout: Maximum wait time in seconds (default: 60)
            require_model_statuses: If True, also requires modelRefStatuses to be populated
                                    (default: False). Set to True for status reporting tests.
    
        Returns:
            The subscription CR dict when the expected phase is reached
    
        Raises:
            TimeoutError: If MaaSSubscription doesn't reach expected phase within timeout
        """
        namespace = namespace or _ns()
        deadline = time.time() + timeout
        log.info(f"Waiting for MaaSSubscription {name} to reach phase '{expected_phase}' (timeout: {timeout}s)...")
    
        while time.time() &lt; deadline:
            cr = _get_cr("maassubscription", name, namespace)
            if cr:
                status = cr.get("status", {})
                phase = status.get("phase")
                model_statuses = status.get("modelRefStatuses", [])
    
                if phase == expected_phase:
                    if require_model_statuses:
                        expected_count = len(cr.get("spec", {}).get("modelRefs", []))
                        if len(model_statuses) &gt;= expected_count:
                            log.info(f"MaaSSubscription {name} reached phase '{expected_phase}' with {len(model_statuses)}/{expected_count} modelRefStatuses")
                            return cr
                    else:
                        log.info(f"MaaSSubscription {name} reached phase '{expected_phase}'")
                        return cr
                log.debug(f"MaaSSubscription {name}: phase={phase}, modelRefStatuses={len(model_statuses)}")
            time.sleep(2)
    
        # Timeout - return current state for debugging
        cr = _get_cr("maassubscription", name, namespace)
        status = cr.get("status", {}) if cr else {}
&gt;       raise TimeoutError(
            f"MaaSSubscription {name} did not reach phase '{expected_phase}' within {timeout}s "
            f"(current: phase={status.get('phase')}, modelRefStatuses={len(status.get('modelRefStatuses', []))})"
        )
E       TimeoutError: MaaSSubscription e2e-enrichment-sub did not reach phase 'Active' within 90s (current: phase=Degraded, modelRefStatuses=1)

test/e2e/tests/test_helper.py:1334: TimeoutError</failure></testcase><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_tenant_namespace_label_change_triggers_reconciliation@mt_lifecycle" time="177.252"><failure message="subprocess.CalledProcessError: Command '['oc', 'apply', '-f', '-']' returned non-zero exit status 1.">self = &lt;test_multi_tenant_integration.TestMultiTenantIntegration object at 0x7f6dae5f10d0&gt;

    def test_tenant_namespace_label_change_triggers_reconciliation(self):
        """7.4: Adding and removing discovery labels changes reconciliation behavior."""
        case = new_discovery_case(use_default_gateway=True)
        first_policy = case["policy_name"]
        second_policy = f"e2e-label-return-{case['suffix']}"
        try:
            ensure_namespace(case["tenant_ns"])
            apply_tenant_cr(case["tenant_ns"], DEFAULT_GATEWAY_NAME)
            apply_maas_auth_policy(first_policy, case["tenant_ns"])
            time.sleep(10)
            first = get_json_or_none("maasauthpolicy", first_policy, case["tenant_ns"])
            assert first is not None
            assert FINALIZER_AUTHPOLICY not in ((first.get("metadata") or {}).get("finalizers") or [])
    
            apply_discovery_labels(case["tenant_ns"], case["tenant_label_name"])
            wait_for_finalizer("maasauthpolicy", first_policy, case["tenant_ns"], FINALIZER_AUTHPOLICY)
    
            remove_discovery_labels(case["tenant_ns"])
            time.sleep(10)
&gt;           apply_maas_auth_policy(second_policy, case["tenant_ns"])

test/e2e/tests/test_multi_tenant_integration.py:220: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:855: in apply_maas_auth_policy
    _apply_cr(
test/e2e/tests/test_helper.py:620: in _apply_cr
    subprocess.run(["oc", "apply", "-f", "-"], input=json.dumps(cr_dict), capture_output=True, text=True, check=True)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

input = '{"apiVersion": "maas.opendatahub.io/v1alpha1", "kind": "MaaSAuthPolicy", "metadata": {"name": "e2e-label-return-f9151...me": "facebook-opt-125m-simulated", "namespace": "llm"}], "subjects": {"groups": [{"name": "system:authenticated"}]}}}'
capture_output = True, timeout = None, check = True
popenargs = (['oc', 'apply', '-f', '-'],)
kwargs = {'stderr': -1, 'stdin': -1, 'stdout': -1, 'text': True}
process = &lt;Popen: returncode: 1 args: ['oc', 'apply', '-f', '-']&gt;, stdout = ''
stderr = 'error: error when retrieving current configuration of:\nResource: "maas.opendatahub.io/v1alpha1, Resource=maasauthpol...a1/namespaces/ai-tenant-e2e-mt-f9151496/maasauthpolicies/e2e-label-return-f9151496": net/http: TLS handshake timeout\n'
retcode = 1

    def run(*popenargs,
            input=None, capture_output=False, timeout=None, check=False, **kwargs):
        """Run command with arguments and return a CompletedProcess instance.
    
        The returned instance will have attributes args, returncode, stdout and
        stderr. By default, stdout and stderr are not captured, and those attributes
        will be None. Pass stdout=PIPE and/or stderr=PIPE in order to capture them.
    
        If check is True and the exit code was non-zero, it raises a
        CalledProcessError. The CalledProcessError object will have the return code
        in the returncode attribute, and output &amp; stderr attributes if those streams
        were captured.
    
        If timeout is given, and the process takes too long, a TimeoutExpired
        exception will be raised.
    
        There is an optional argument "input", allowing you to
        pass bytes or a string to the subprocess's stdin.  If you use this argument
        you may not also use the Popen constructor's "stdin" argument, as
        it will be used internally.
    
        By default, all communication is in bytes, and therefore any "input" should
        be bytes, and the stdout and stderr will be bytes. If in text mode, any
        "input" should be a string, and stdout and stderr will be strings decoded
        according to locale encoding, or by "encoding" if set. Text mode is
        triggered by setting any of text, encoding, errors or universal_newlines.
    
        The other arguments are the same as for the Popen constructor.
        """
        if input is not None:
            if kwargs.get('stdin') is not None:
                raise ValueError('stdin and input arguments may not both be used.')
            kwargs['stdin'] = PIPE
    
        if capture_output:
            if kwargs.get('stdout') is not None or kwargs.get('stderr') is not None:
                raise ValueError('stdout and stderr arguments may not be used '
                                 'with capture_output.')
            kwargs['stdout'] = PIPE
            kwargs['stderr'] = PIPE
    
        with Popen(*popenargs, **kwargs) as process:
            try:
                stdout, stderr = process.communicate(input, timeout=timeout)
            except TimeoutExpired as exc:
                process.kill()
                if _mswindows:
                    # Windows accumulates the output in a single blocking
                    # read() call run on child threads, with the timeout
                    # being done in a join() on those threads.  communicate()
                    # _after_ kill() is required to collect that and add it
                    # to the exception.
                    exc.stdout, exc.stderr = process.communicate()
                else:
                    # POSIX _communicate already populated the output so
                    # far into the TimeoutExpired exception.
                    process.wait()
                raise
            except:  # Including KeyboardInterrupt, communicate handled that.
                process.kill()
                # We don't call process.wait() as .__exit__ does that for us.
                raise
            retcode = process.poll()
            if check and retcode:
&gt;               raise CalledProcessError(retcode, process.args,
                                         output=stdout, stderr=stderr)
E               subprocess.CalledProcessError: Command '['oc', 'apply', '-f', '-']' returned non-zero exit status 1.

/usr/lib64/python3.9/subprocess.py:528: CalledProcessError</failure></testcase><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_creation_scoped_to_tenant@tenant_isolation" time="167.641"><error message="failed on setup with &quot;RuntimeError: `oc get llminferenceservice auth-test-model-231820 -o json -n ai-tenant-e2e-shared-b-w3-231820` failed: Unable to connect to the server: net/http: TLS handshake timeout&quot;">shared_test_tenants = ({'base_url': 'https://e2e-shared-a-w3-771942.apps.4fa2f5a5-8971-4ad5-8356-5e19d1253a2c.prod.konfluxeaas.com/maas-api'...me': 'e2e-shared-b-w3-231820', 'name': 'e2e-shared-b-w3-231820', 'namespace': 'ai-tenant-e2e-shared-b-w3-231820', ...})

    @pytest.fixture(scope="module")
    def tenant_env(shared_test_tenants):
        """Adapter fixture with tenant-specific models."""
        case_a, case_b = dict(shared_test_tenants[0]), dict(shared_test_tenants[1])
    
        for case in (case_a, case_b):
            model_name = f"auth-test-model-{case['suffix']}"
&gt;           provision_tenant_model(model_name, case["tenant_ns"], case["gateway_name"])

test/e2e/tests/test_tenant_auth_isolation.py:99: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:959: in provision_tenant_model
    wait_for_llmisvc_backend_ready(
test/e2e/tests/multitenancy_helpers.py:706: in wait_for_llmisvc_backend_ready
    llmisvc = wait_for_status_condition(
test/e2e/tests/multitenancy_helpers.py:303: in wait_for_status_condition
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
test/e2e/tests/multitenancy_helpers.py:223: in wait_for_json
    obj = get_json_or_none(kind, name, namespace)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'llminferenceservice', name = 'auth-test-model-231820'
namespace = 'ai-tenant-e2e-shared-b-w3-231820'

    def get_json_or_none(kind: str, name: str, namespace: Optional[str] = None) -&gt; Optional[dict]:
        args = ["get", kind, name, "-o", "json"]
        if namespace:
            args.extend(["-n", namespace])
        result = _oc_run(args)
        if result.returncode == 0:
            return json.loads(result.stdout)
        if _oc_output_not_found(result):
            return None
&gt;       raise RuntimeError(f"`oc {' '.join(args)}` failed: {result.stderr.strip() or result.stdout.strip()}")
E       RuntimeError: `oc get llminferenceservice auth-test-model-231820 -o json -n ai-tenant-e2e-shared-b-w3-231820` failed: Unable to connect to the server: net/http: TLS handshake timeout

test/e2e/tests/multitenancy_helpers.py:194: RuntimeError</error></testcase><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_explicit_subscription_header@models" time="67.375"><error message="failed on setup with &quot;RuntimeError: `oc get llminferenceservice distinct-w4-5cedb0 -o json -n e2e-models-e2e-worker-w4-5cedb0` failed: Unable to connect to the server: net/http: TLS handshake timeout&quot;">request = &lt;SubRequest '_worker_models_context' for &lt;Function test_explicit_subscription_header&gt;&gt;

    @pytest.fixture(scope="module", autouse=True)
    def _worker_models_context(request):
        """Route parallel model tests through the explicit worker context.
    
        The serial pass intentionally retains the default deployment.
        """
        from worker_tenant_fixtures import (
            activate_worker_tenant,
            ensure_worker_models,
            serial_only_selection,
        )
    
        if serial_only_selection(request):
            yield
            return
    
        context = request.getfixturevalue("worker_tenant_context")
&gt;       ensure_worker_models(
            context,
            (
                context.distinct_model_ref,
                context.distinct_model_2_ref,
            ),
        )

test/e2e/tests/test_models_endpoint.py:93: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/worker_tenant_fixtures.py:304: in ensure_worker_models
    wait_for_llmisvc_backend_ready(
test/e2e/tests/multitenancy_helpers.py:706: in wait_for_llmisvc_backend_ready
    llmisvc = wait_for_status_condition(
test/e2e/tests/multitenancy_helpers.py:303: in wait_for_status_condition
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
test/e2e/tests/multitenancy_helpers.py:223: in wait_for_json
    obj = get_json_or_none(kind, name, namespace)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'llminferenceservice', name = 'distinct-w4-5cedb0'
namespace = 'e2e-models-e2e-worker-w4-5cedb0'

    def get_json_or_none(kind: str, name: str, namespace: Optional[str] = None) -&gt; Optional[dict]:
        args = ["get", kind, name, "-o", "json"]
        if namespace:
            args.extend(["-n", namespace])
        result = _oc_run(args)
        if result.returncode == 0:
            return json.loads(result.stdout)
        if _oc_output_not_found(result):
            return None
&gt;       raise RuntimeError(f"`oc {' '.join(args)}` failed: {result.stderr.strip() or result.stdout.strip()}")
E       RuntimeError: `oc get llminferenceservice distinct-w4-5cedb0 -o json -n e2e-models-e2e-worker-w4-5cedb0` failed: Unable to connect to the server: net/http: TLS handshake timeout

test/e2e/tests/multitenancy_helpers.py:194: RuntimeError</error></testcase><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_validates_against_correct_tenant@tenant_isolation" time="0.000"><error message="failed on setup with &quot;RuntimeError: `oc get llminferenceservice auth-test-model-231820 -o json -n ai-tenant-e2e-shared-b-w3-231820` failed: Unable to connect to the server: net/http: TLS handshake timeout&quot;">shared_test_tenants = ({'base_url': 'https://e2e-shared-a-w3-771942.apps.4fa2f5a5-8971-4ad5-8356-5e19d1253a2c.prod.konfluxeaas.com/maas-api'...me': 'e2e-shared-b-w3-231820', 'name': 'e2e-shared-b-w3-231820', 'namespace': 'ai-tenant-e2e-shared-b-w3-231820', ...})

    @pytest.fixture(scope="module")
    def tenant_env(shared_test_tenants):
        """Adapter fixture with tenant-specific models."""
        case_a, case_b = dict(shared_test_tenants[0]), dict(shared_test_tenants[1])
    
        for case in (case_a, case_b):
            model_name = f"auth-test-model-{case['suffix']}"
&gt;           provision_tenant_model(model_name, case["tenant_ns"], case["gateway_name"])

test/e2e/tests/test_tenant_auth_isolation.py:99: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:959: in provision_tenant_model
    wait_for_llmisvc_backend_ready(
test/e2e/tests/multitenancy_helpers.py:706: in wait_for_llmisvc_backend_ready
    llmisvc = wait_for_status_condition(
test/e2e/tests/multitenancy_helpers.py:303: in wait_for_status_condition
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
test/e2e/tests/multitenancy_helpers.py:223: in wait_for_json
    obj = get_json_or_none(kind, name, namespace)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'llminferenceservice', name = 'auth-test-model-231820'
namespace = 'ai-tenant-e2e-shared-b-w3-231820'

    def get_json_or_none(kind: str, name: str, namespace: Optional[str] = None) -&gt; Optional[dict]:
        args = ["get", kind, name, "-o", "json"]
        if namespace:
            args.extend(["-n", namespace])
        result = _oc_run(args)
        if result.returncode == 0:
            return json.loads(result.stdout)
        if _oc_output_not_found(result):
            return None
&gt;       raise RuntimeError(f"`oc {' '.join(args)}` failed: {result.stderr.strip() or result.stdout.strip()}")
E       RuntimeError: `oc get llminferenceservice auth-test-model-231820 -o json -n ai-tenant-e2e-shared-b-w3-231820` failed: Unable to connect to the server: net/http: TLS handshake timeout

test/e2e/tests/multitenancy_helpers.py:194: RuntimeError</error></testcase><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_empty_subscription_header_value@models" time="0.000"><error message="failed on setup with &quot;RuntimeError: `oc get llminferenceservice distinct-w4-5cedb0 -o json -n e2e-models-e2e-worker-w4-5cedb0` failed: Unable to connect to the server: net/http: TLS handshake timeout&quot;">request = &lt;SubRequest '_worker_models_context' for &lt;Function test_explicit_subscription_header&gt;&gt;

    @pytest.fixture(scope="module", autouse=True)
    def _worker_models_context(request):
        """Route parallel model tests through the explicit worker context.
    
        The serial pass intentionally retains the default deployment.
        """
        from worker_tenant_fixtures import (
            activate_worker_tenant,
            ensure_worker_models,
            serial_only_selection,
        )
    
        if serial_only_selection(request):
            yield
            return
    
        context = request.getfixturevalue("worker_tenant_context")
&gt;       ensure_worker_models(
            context,
            (
                context.distinct_model_ref,
                context.distinct_model_2_ref,
            ),
        )

test/e2e/tests/test_models_endpoint.py:93: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/worker_tenant_fixtures.py:304: in ensure_worker_models
    wait_for_llmisvc_backend_ready(
test/e2e/tests/multitenancy_helpers.py:706: in wait_for_llmisvc_backend_ready
    llmisvc = wait_for_status_condition(
test/e2e/tests/multitenancy_helpers.py:303: in wait_for_status_condition
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
test/e2e/tests/multitenancy_helpers.py:223: in wait_for_json
    obj = get_json_or_none(kind, name, namespace)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'llminferenceservice', name = 'distinct-w4-5cedb0'
namespace = 'e2e-models-e2e-worker-w4-5cedb0'

    def get_json_or_none(kind: str, name: str, namespace: Optional[str] = None) -&gt; Optional[dict]:
        args = ["get", kind, name, "-o", "json"]
        if namespace:
            args.extend(["-n", namespace])
        result = _oc_run(args)
        if result.returncode == 0:
            return json.loads(result.stdout)
        if _oc_output_not_found(result):
            return None
&gt;       raise RuntimeError(f"`oc {' '.join(args)}` failed: {result.stderr.strip() or result.stdout.strip()}")
E       RuntimeError: `oc get llminferenceservice distinct-w4-5cedb0 -o json -n e2e-models-e2e-worker-w4-5cedb0` failed: Unable to connect to the server: net/http: TLS handshake timeout

test/e2e/tests/multitenancy_helpers.py:194: RuntimeError</error></testcase><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_rejected_cross_tenant@tenant_isolation" time="0.000"><error message="failed on setup with &quot;RuntimeError: `oc get llminferenceservice auth-test-model-231820 -o json -n ai-tenant-e2e-shared-b-w3-231820` failed: Unable to connect to the server: net/http: TLS handshake timeout&quot;">shared_test_tenants = ({'base_url': 'https://e2e-shared-a-w3-771942.apps.4fa2f5a5-8971-4ad5-8356-5e19d1253a2c.prod.konfluxeaas.com/maas-api'...me': 'e2e-shared-b-w3-231820', 'name': 'e2e-shared-b-w3-231820', 'namespace': 'ai-tenant-e2e-shared-b-w3-231820', ...})

    @pytest.fixture(scope="module")
    def tenant_env(shared_test_tenants):
        """Adapter fixture with tenant-specific models."""
        case_a, case_b = dict(shared_test_tenants[0]), dict(shared_test_tenants[1])
    
        for case in (case_a, case_b):
            model_name = f"auth-test-model-{case['suffix']}"
&gt;           provision_tenant_model(model_name, case["tenant_ns"], case["gateway_name"])

test/e2e/tests/test_tenant_auth_isolation.py:99: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:959: in provision_tenant_model
    wait_for_llmisvc_backend_ready(
test/e2e/tests/multitenancy_helpers.py:706: in wait_for_llmisvc_backend_ready
    llmisvc = wait_for_status_condition(
test/e2e/tests/multitenancy_helpers.py:303: in wait_for_status_condition
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
test/e2e/tests/multitenancy_helpers.py:223: in wait_for_json
    obj = get_json_or_none(kind, name, namespace)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'llminferenceservice', name = 'auth-test-model-231820'
namespace = 'ai-tenant-e2e-shared-b-w3-231820'

    def get_json_or_none(kind: str, name: str, namespace: Optional[str] = None) -&gt; Optional[dict]:
        args = ["get", kind, name, "-o", "json"]
        if namespace:
            args.extend(["-n", namespace])
        result = _oc_run(args)
        if result.returncode == 0:
            return json.loads(result.stdout)
        if _oc_output_not_found(result):
            return None
&gt;       raise RuntimeError(f"`oc {' '.join(args)}` failed: {result.stderr.strip() or result.stdout.strip()}")
E       RuntimeError: `oc get llminferenceservice auth-test-model-231820 -o json -n ai-tenant-e2e-shared-b-w3-231820` failed: Unable to connect to the server: net/http: TLS handshake timeout

test/e2e/tests/multitenancy_helpers.py:194: RuntimeError</error></testcase><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_oidc_token_validation_per_tenant@tenant_isolation" time="0.000"><error message="failed on setup with &quot;RuntimeError: `oc get llminferenceservice auth-test-model-231820 -o json -n ai-tenant-e2e-shared-b-w3-231820` failed: Unable to connect to the server: net/http: TLS handshake timeout&quot;">shared_test_tenants = ({'base_url': 'https://e2e-shared-a-w3-771942.apps.4fa2f5a5-8971-4ad5-8356-5e19d1253a2c.prod.konfluxeaas.com/maas-api'...me': 'e2e-shared-b-w3-231820', 'name': 'e2e-shared-b-w3-231820', 'namespace': 'ai-tenant-e2e-shared-b-w3-231820', ...})

    @pytest.fixture(scope="module")
    def tenant_env(shared_test_tenants):
        """Adapter fixture with tenant-specific models."""
        case_a, case_b = dict(shared_test_tenants[0]), dict(shared_test_tenants[1])
    
        for case in (case_a, case_b):
            model_name = f"auth-test-model-{case['suffix']}"
&gt;           provision_tenant_model(model_name, case["tenant_ns"], case["gateway_name"])

test/e2e/tests/test_tenant_auth_isolation.py:99: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:959: in provision_tenant_model
    wait_for_llmisvc_backend_ready(
test/e2e/tests/multitenancy_helpers.py:706: in wait_for_llmisvc_backend_ready
    llmisvc = wait_for_status_condition(
test/e2e/tests/multitenancy_helpers.py:303: in wait_for_status_condition
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
test/e2e/tests/multitenancy_helpers.py:223: in wait_for_json
    obj = get_json_or_none(kind, name, namespace)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'llminferenceservice', name = 'auth-test-model-231820'
namespace = 'ai-tenant-e2e-shared-b-w3-231820'

    def get_json_or_none(kind: str, name: str, namespace: Optional[str] = None) -&gt; Optional[dict]:
        args = ["get", kind, name, "-o", "json"]
        if namespace:
            args.extend(["-n", namespace])
        result = _oc_run(args)
        if result.returncode == 0:
            return json.loads(result.stdout)
        if _oc_output_not_found(result):
            return None
&gt;       raise RuntimeError(f"`oc {' '.join(args)}` failed: {result.stderr.strip() or result.stdout.strip()}")
E       RuntimeError: `oc get llminferenceservice auth-test-model-231820 -o json -n ai-tenant-e2e-shared-b-w3-231820` failed: Unable to connect to the server: net/http: TLS handshake timeout

test/e2e/tests/multitenancy_helpers.py:194: RuntimeError</error></testcase><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_models_filtered_by_subscription@models" time="0.000"><error message="failed on setup with &quot;RuntimeError: `oc get llminferenceservice distinct-w4-5cedb0 -o json -n e2e-models-e2e-worker-w4-5cedb0` failed: Unable to connect to the server: net/http: TLS handshake timeout&quot;">request = &lt;SubRequest '_worker_models_context' for &lt;Function test_explicit_subscription_header&gt;&gt;

    @pytest.fixture(scope="module", autouse=True)
    def _worker_models_context(request):
        """Route parallel model tests through the explicit worker context.
    
        The serial pass intentionally retains the default deployment.
        """
        from worker_tenant_fixtures import (
            activate_worker_tenant,
            ensure_worker_models,
            serial_only_selection,
        )
    
        if serial_only_selection(request):
            yield
            return
    
        context = request.getfixturevalue("worker_tenant_context")
&gt;       ensure_worker_models(
            context,
            (
                context.distinct_model_ref,
                context.distinct_model_2_ref,
            ),
        )

test/e2e/tests/test_models_endpoint.py:93: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/worker_tenant_fixtures.py:304: in ensure_worker_models
    wait_for_llmisvc_backend_ready(
test/e2e/tests/multitenancy_helpers.py:706: in wait_for_llmisvc_backend_ready
    llmisvc = wait_for_status_condition(
test/e2e/tests/multitenancy_helpers.py:303: in wait_for_status_condition
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
test/e2e/tests/multitenancy_helpers.py:223: in wait_for_json
    obj = get_json_or_none(kind, name, namespace)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'llminferenceservice', name = 'distinct-w4-5cedb0'
namespace = 'e2e-models-e2e-worker-w4-5cedb0'

    def get_json_or_none(kind: str, name: str, namespace: Optional[str] = None) -&gt; Optional[dict]:
        args = ["get", kind, name, "-o", "json"]
        if namespace:
            args.extend(["-n", namespace])
        result = _oc_run(args)
        if result.returncode == 0:
            return json.loads(result.stdout)
        if _oc_output_not_found(result):
            return None
&gt;       raise RuntimeError(f"`oc {' '.join(args)}` failed: {result.stderr.strip() or result.stdout.strip()}")
E       RuntimeError: `oc get llminferenceservice distinct-w4-5cedb0 -o json -n e2e-models-e2e-worker-w4-5cedb0` failed: Unable to connect to the server: net/http: TLS handshake timeout

test/e2e/tests/multitenancy_helpers.py:194: RuntimeError</error></testcase><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_list_scoped_to_tenant@tenant_isolation" time="255.471"><error message="failed on setup with &quot;RuntimeError: `oc get llminferenceservice auth-test-model-231820 -o json -n ai-tenant-e2e-shared-b-w3-231820` failed: Unable to connect to the server: net/http: TLS handshake timeout&quot;">shared_test_tenants = ({'base_url': 'https://e2e-shared-a-w3-771942.apps.4fa2f5a5-8971-4ad5-8356-5e19d1253a2c.prod.konfluxeaas.com/maas-api'...me': 'e2e-shared-b-w3-231820', 'name': 'e2e-shared-b-w3-231820', 'namespace': 'ai-tenant-e2e-shared-b-w3-231820', ...})

    @pytest.fixture(scope="module")
    def tenant_env(shared_test_tenants):
        """Adapter fixture with tenant-specific models."""
        case_a, case_b = dict(shared_test_tenants[0]), dict(shared_test_tenants[1])
    
        for case in (case_a, case_b):
            model_name = f"auth-test-model-{case['suffix']}"
&gt;           provision_tenant_model(model_name, case["tenant_ns"], case["gateway_name"])

test/e2e/tests/test_tenant_auth_isolation.py:99: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:959: in provision_tenant_model
    wait_for_llmisvc_backend_ready(
test/e2e/tests/multitenancy_helpers.py:706: in wait_for_llmisvc_backend_ready
    llmisvc = wait_for_status_condition(
test/e2e/tests/multitenancy_helpers.py:303: in wait_for_status_condition
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
test/e2e/tests/multitenancy_helpers.py:223: in wait_for_json
    obj = get_json_or_none(kind, name, namespace)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'llminferenceservice', name = 'auth-test-model-231820'
namespace = 'ai-tenant-e2e-shared-b-w3-231820'

    def get_json_or_none(kind: str, name: str, namespace: Optional[str] = None) -&gt; Optional[dict]:
        args = ["get", kind, name, "-o", "json"]
        if namespace:
            args.extend(["-n", namespace])
        result = _oc_run(args)
        if result.returncode == 0:
            return json.loads(result.stdout)
        if _oc_output_not_found(result):
            return None
&gt;       raise RuntimeError(f"`oc {' '.join(args)}` failed: {result.stderr.strip() or result.stdout.strip()}")
E       RuntimeError: `oc get llminferenceservice auth-test-model-231820 -o json -n ai-tenant-e2e-shared-b-w3-231820` failed: Unable to connect to the server: net/http: TLS handshake timeout

test/e2e/tests/multitenancy_helpers.py:194: RuntimeError</error></testcase><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_deduplication_same_model_multiple_refs@models" time="0.000"><error message="failed on setup with &quot;RuntimeError: `oc get llminferenceservice distinct-w4-5cedb0 -o json -n e2e-models-e2e-worker-w4-5cedb0` failed: Unable to connect to the server: net/http: TLS handshake timeout&quot;">request = &lt;SubRequest '_worker_models_context' for &lt;Function test_explicit_subscription_header&gt;&gt;

    @pytest.fixture(scope="module", autouse=True)
    def _worker_models_context(request):
        """Route parallel model tests through the explicit worker context.
    
        The serial pass intentionally retains the default deployment.
        """
        from worker_tenant_fixtures import (
            activate_worker_tenant,
            ensure_worker_models,
            serial_only_selection,
        )
    
        if serial_only_selection(request):
            yield
            return
    
        context = request.getfixturevalue("worker_tenant_context")
&gt;       ensure_worker_models(
            context,
            (
                context.distinct_model_ref,
                context.distinct_model_2_ref,
            ),
        )

test/e2e/tests/test_models_endpoint.py:93: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/worker_tenant_fixtures.py:304: in ensure_worker_models
    wait_for_llmisvc_backend_ready(
test/e2e/tests/multitenancy_helpers.py:706: in wait_for_llmisvc_backend_ready
    llmisvc = wait_for_status_condition(
test/e2e/tests/multitenancy_helpers.py:303: in wait_for_status_condition
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
test/e2e/tests/multitenancy_helpers.py:223: in wait_for_json
    obj = get_json_or_none(kind, name, namespace)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'llminferenceservice', name = 'distinct-w4-5cedb0'
namespace = 'e2e-models-e2e-worker-w4-5cedb0'

    def get_json_or_none(kind: str, name: str, namespace: Optional[str] = None) -&gt; Optional[dict]:
        args = ["get", kind, name, "-o", "json"]
        if namespace:
            args.extend(["-n", namespace])
        result = _oc_run(args)
        if result.returncode == 0:
            return json.loads(result.stdout)
        if _oc_output_not_found(result):
            return None
&gt;       raise RuntimeError(f"`oc {' '.join(args)}` failed: {result.stderr.strip() or result.stdout.strip()}")
E       RuntimeError: `oc get llminferenceservice distinct-w4-5cedb0 -o json -n e2e-models-e2e-worker-w4-5cedb0` failed: Unable to connect to the server: net/http: TLS handshake timeout

test/e2e/tests/multitenancy_helpers.py:194: RuntimeError</error></testcase><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_multiple_distinct_models_in_subscription@models" time="159.726"><error message="failed on setup with &quot;RuntimeError: `oc get llminferenceservice distinct-w4-5cedb0 -o json -n e2e-models-e2e-worker-w4-5cedb0` failed: Unable to connect to the server: net/http: TLS handshake timeout&quot;">request = &lt;SubRequest '_worker_models_context' for &lt;Function test_explicit_subscription_header&gt;&gt;

    @pytest.fixture(scope="module", autouse=True)
    def _worker_models_context(request):
        """Route parallel model tests through the explicit worker context.
    
        The serial pass intentionally retains the default deployment.
        """
        from worker_tenant_fixtures import (
            activate_worker_tenant,
            ensure_worker_models,
            serial_only_selection,
        )
    
        if serial_only_selection(request):
            yield
            return
    
        context = request.getfixturevalue("worker_tenant_context")
&gt;       ensure_worker_models(
            context,
            (
                context.distinct_model_ref,
                context.distinct_model_2_ref,
            ),
        )

test/e2e/tests/test_models_endpoint.py:93: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/worker_tenant_fixtures.py:304: in ensure_worker_models
    wait_for_llmisvc_backend_ready(
test/e2e/tests/multitenancy_helpers.py:706: in wait_for_llmisvc_backend_ready
    llmisvc = wait_for_status_condition(
test/e2e/tests/multitenancy_helpers.py:303: in wait_for_status_condition
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
test/e2e/tests/multitenancy_helpers.py:223: in wait_for_json
    obj = get_json_or_none(kind, name, namespace)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'llminferenceservice', name = 'distinct-w4-5cedb0'
namespace = 'e2e-models-e2e-worker-w4-5cedb0'

    def get_json_or_none(kind: str, name: str, namespace: Optional[str] = None) -&gt; Optional[dict]:
        args = ["get", kind, name, "-o", "json"]
        if namespace:
            args.extend(["-n", namespace])
        result = _oc_run(args)
        if result.returncode == 0:
            return json.loads(result.stdout)
        if _oc_output_not_found(result):
            return None
&gt;       raise RuntimeError(f"`oc {' '.join(args)}` failed: {result.stderr.strip() or result.stdout.strip()}")
E       RuntimeError: `oc get llminferenceservice distinct-w4-5cedb0 -o json -n e2e-models-e2e-worker-w4-5cedb0` failed: Unable to connect to the server: net/http: TLS handshake timeout

test/e2e/tests/multitenancy_helpers.py:194: RuntimeError</error></testcase><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptionsForModel" name="test_returns_subscriptions_for_model@api_keys" time="41.337"><failure message="AssertionError: Expected 200, got 500: {&quot;error&quot;:&quot;Exception thrown while generating token&quot;,&quot;exceptionCode&quot;:&quot;AUTH_FAILURE&quot;,&quot;refId&quot;:&quot;001&quot;}&#10;assert 500 == 200&#10; +  where 500 = &lt;Response [500]&gt;.status_code">self = &lt;test_subscription_list_endpoints.TestListSubscriptionsForModel object at 0x7fcad8b02370&gt;

    def test_returns_subscriptions_for_model(self):
        """Returns only subscriptions that include the requested model."""
        sa_name = "e2e-subs-model-sa"
        sa_ns = "default"
        maas_ns = _ns()
        sub_with_model = "e2e-model-match-sub"
        sub_without_model = "e2e-model-nomatch-sub"
    
        ap_with_model = "e2e-model-match-auth"
        ap_without_model = "e2e-model-nomatch-auth"
    
        try:
            sa_token = _create_sa_token(sa_name, namespace=sa_ns)
            sa_user = _sa_to_user(sa_name, namespace=sa_ns)
    
            # Create two subscriptions: one with DISTINCT_MODEL_REF, one with DISTINCT_MODEL_2_REF
            _create_test_subscription(sub_with_model, DISTINCT_MODEL_REF, users=[sa_user])
            _create_test_subscription(sub_without_model, DISTINCT_MODEL_2_REF, users=[sa_user])
    
            _create_test_auth_policy(ap_with_model, DISTINCT_MODEL_REF, users=[sa_user])
            _create_test_auth_policy(ap_without_model, DISTINCT_MODEL_2_REF, users=[sa_user])
    
            api_key = _create_api_key(sa_token, name=f"{sa_name}-key")
    
            _wait_for_maas_subscription_phase(sub_with_model, namespace=maas_ns)
            _wait_for_maas_subscription_phase(sub_without_model, namespace=maas_ns)
    
            _wait_for_maas_auth_policy_phase(ap_with_model, require_enforced=False, namespace=maas_ns)
            _wait_for_maas_auth_policy_phase(ap_without_model, require_enforced=False, namespace=maas_ns)
    
            # Query for subscriptions that include DISTINCT_MODEL_REF
            url = f"{_maas_api_url()}/v1/model/{DISTINCT_MODEL_REF}/subscriptions"
            r = requests.get(
                url,
                headers={"Authorization": f"Bearer {api_key}"},
                timeout=TIMEOUT,
                verify=TLS_VERIFY,
            )
    
&gt;           assert r.status_code == 200, f"Expected 200, got {r.status_code}: {r.text}"
E           AssertionError: Expected 200, got 500: {"error":"Exception thrown while generating token","exceptionCode":"AUTH_FAILURE","refId":"001"}
E           assert 500 == 200
E            +  where 500 = &lt;Response [500]&gt;.status_code

test/e2e/tests/test_subscription_list_endpoints.py:407: AssertionError</failure></testcase><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptionsForModel" name="test_unknown_model_returns_empty@api_keys" time="0.483" /><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptionsForModel" name="test_unauthenticated_returns_401@api_keys" time="0.031" /><testcase classname="tests.test_subscription_list_endpoints.TestSubscriptionModelAccessFiltering" name="test_filters_unauthorized_models@api_keys" time="21.524" /><testcase classname="tests.test_subscription_list_endpoints.TestSubscriptionModelAccessFiltering" name="test_omits_subscription_with_no_authorized_models@api_keys" time="12.315" /><testcase classname="tests.test_embedding_inference.TestEmbeddingPathRouting" name="test_embedding_path_based_200@api_keys" time="41.325" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_aitenant_creates_dedicated_maas_api_infrastructure@mt_lifecycle" time="65.868" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_tenant_name_environment_variable_set@mt_lifecycle" time="0.225" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_service_routing_isolation@mt_lifecycle" time="0.451" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_httproute_tenant_attachment@mt_lifecycle" time="0.220" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_default_and_multiple_tenants_coexist@mt_lifecycle" time="96.363" /><testcase classname="tests.test_embedding_inference.TestEmbeddingPathRouting" name="test_embedding_bbr_llmisvc_200@api_keys" time="45.371" /></testsuite></testsuites>