<?xml version="1.0" encoding="utf-8"?><testsuites name="pytest tests"><testsuite name="pytest" errors="0" failures="3" skipped="1" tests="127" time="1228.067" timestamp="2026-04-20T15:08:45.091397+00:00" hostname="maas-group-test-s9qb9-e2e-maas-openshift-pod"><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyCRUD" name="test_create_api_key" time="0.106" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyCRUD" name="test_list_api_keys" time="0.132" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyCRUD" name="test_revoke_api_key" time="0.096" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyAuthorization" name="test_admin_manage_other_users_keys" time="0.133" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyAuthorization" name="test_non_admin_cannot_access_other_users_keys" time="0.097" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_own_keys" time="0.254" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_other_user_forbidden" time="0.035" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_admin_can_revoke_any_user" time="0.096" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_within_expiration_limit" time="0.030" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_at_expiration_limit" time="0.030" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_exceeds_expiration_limit" time="0.029" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_without_expiration" time="0.036" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_with_short_expiration" time="0.032" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_api_key_model_access_success" time="0.108" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_invalid_api_key_rejected" time="0.024" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_no_auth_header_rejected" time="0.019" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_revoked_api_key_rejected" time="2.117" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_api_key_chat_completions" time="0.027" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_double_revoke_returns_404" time="0.096" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_nonexistent_key_returns_404" time="0.031" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_then_create_new_key_works" time="0.145" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_individual_revoke_multiple_keys" time="0.187" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_keys_rejected_at_gateway" time="0.275" /><testcase classname="test.e2e.tests.test_api_keys.TestEphemeralKeyCleanup" name="test_cronjob_exists_and_configured" time="0.109" /><testcase classname="test.e2e.tests.test_api_keys.TestEphemeralKeyCleanup" name="test_cleanup_networkpolicy_exists" time="0.113" /><testcase classname="test.e2e.tests.test_api_keys.TestEphemeralKeyCleanup" name="test_create_ephemeral_key" time="0.094" /><testcase classname="test.e2e.tests.test_api_keys.TestEphemeralKeyCleanup" name="test_trigger_cleanup_preserves_active_keys" time="0.585"><skipped type="pytest.skip" message="Cannot exec into maas-api pod to trigger cleanup (neither curl nor wget available): executable file `wget` not found in $PATH: No such file or directory&#10;command terminated with exit code 1">/workspace/source/test/e2e/tests/test_api_keys.py:1083: Cannot exec into maas-api pod to trigger cleanup (neither curl nor wget available): executable file `wget` not found in $PATH: No such file or directory
command terminated with exit code 1</skipped></testcase><testcase classname="test.e2e.tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_subscription_namespace_visible_to_api" time="16.416" /><testcase classname="test.e2e.tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_another_namespace_not_visible_to_api" time="22.612" /><testcase classname="test.e2e.tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_maas_subscription_namespace" time="23.953" /><testcase classname="test.e2e.tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_another_namespace" time="29.623" /><testcase classname="test.e2e.tests.test_namespace_scoping.TestModelRef" name="test_auth_policy_model_ref" time="31.150" /><testcase classname="test.e2e.tests.test_namespace_scoping.TestModelRef" name="test_subscription_model_ref" time="31.236" /><testcase classname="test.e2e.tests.test_negative_security.TestHeaderSpoofing" name="test_injected_identity_headers_ignored" time="0.082" /><testcase classname="test.e2e.tests.test_negative_security.TestHeaderSpoofing" name="test_duplicate_subscription_headers_ignored" time="0.075" /><testcase classname="test.e2e.tests.test_negative_security.TestExpiredKeyRejection" name="test_expired_key_rejected_at_gateway" time="5.067" /><testcase classname="test.e2e.tests.test_negative_security.TestCrossModelAccess" name="test_key_cannot_access_model_outside_subscription" time="0.062" /><testcase classname="test.e2e.tests.test_negative_security.TestAuthPolicyRemoval" name="test_authpolicy_deletion_revokes_access" time="5.032" /><testcase classname="test.e2e.tests.test_negative_security.TestMissingModelRef" name="test_subscription_with_nonexistent_model_ref" time="1.018" /><testcase classname="test.e2e.tests.test_negative_security.TestMissingModelRef" name="test_authpolicy_with_nonexistent_model_ref" time="0.672" /><testcase classname="test.e2e.tests.test_negative_security.TestHeaderAbuse" name="test_special_characters_in_subscription_header" time="0.145" /><testcase classname="test.e2e.tests.test_subscription.TestAuthEnforcement" name="test_authorized_user_gets_200" time="0.066" /><testcase classname="test.e2e.tests.test_subscription.TestAuthEnforcement" name="test_no_auth_gets_401" time="0.020" /><testcase classname="test.e2e.tests.test_subscription.TestAuthEnforcement" name="test_invalid_token_gets_403" time="0.023" /><testcase classname="test.e2e.tests.test_subscription.TestAuthEnforcement" name="test_wrong_group_gets_403" time="0.024" /><testcase classname="test.e2e.tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_uses_highest_priority_subscription" time="0.287" /><testcase classname="test.e2e.tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_with_explicit_simulator_subscription" time="0.063" /><testcase classname="test.e2e.tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_nonexistent_subscription_errors" time="0.248" /><testcase classname="test.e2e.tests.test_subscription.TestSubscriptionEnforcement" name="test_subscribed_user_gets_200" time="0.030" /><testcase classname="test.e2e.tests.test_subscription.TestSubscriptionEnforcement" name="test_auth_pass_no_subscription_gets_403" time="16.402" /><testcase classname="test.e2e.tests.test_subscription.TestSubscriptionEnforcement" name="test_rate_limit_exhaustion_gets_429" time="25.575" /><testcase classname="test.e2e.tests.test_subscription.TestSubscriptionEnforcement" name="test_models_endpoint_exempt_from_rate_limiting" time="25.210" /><testcase classname="test.e2e.tests.test_subscription.TestMultipleSubscriptionsPerModel" name="test_user_in_one_of_two_subscriptions_gets_200" time="8.386" /><testcase classname="test.e2e.tests.test_subscription.TestMultipleAuthPoliciesPerModel" name="test_two_auth_policies_or_logic" time="16.822" /><testcase classname="test.e2e.tests.test_subscription.TestMultipleAuthPoliciesPerModel" name="test_delete_one_auth_policy_other_still_works" time="24.539" /><testcase classname="test.e2e.tests.test_subscription.TestCascadeDeletion" name="test_delete_subscription_rebuilds_trlp" time="8.513" /><testcase classname="test.e2e.tests.test_subscription.TestCascadeDeletion" name="test_trlp_persists_during_multi_subscription_deletion" time="33.288" /><testcase classname="test.e2e.tests.test_subscription.TestCascadeDeletion" name="test_delete_last_subscription_denies_access" time="8.489" /><testcase classname="test.e2e.tests.test_subscription.TestCascadeDeletion" name="test_unconfigured_model_denied_by_gateway_auth" time="0.476" /><testcase classname="test.e2e.tests.test_subscription.TestOrderingEdgeCases" name="test_subscription_before_auth_policy" time="18.945" /><testcase classname="test.e2e.tests.test_subscription.TestManagedAnnotation" name="test_authpolicy_managed_false_prevents_update" time="20.477" /><testcase classname="test.e2e.tests.test_subscription.TestManagedAnnotation" name="test_trlp_managed_false_prevents_update" time="17.467" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_both_access_and_subscription_gets_200" time="17.810" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_access_but_no_subscription_gets_403" time="17.210" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_subscription_but_no_access_gets_403" time="17.906" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_single_subscription_auto_selects" time="17.554" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_multiple_subscriptions_separate_keys_gets_200" time="17.532" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_mint_api_key_denied_for_inaccessible_subscription" time="17.734" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_access_gets_200" time="17.099" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_auth_but_no_subscription_gets_403" time="17.193" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_subscription_but_no_auth_gets_403" time="17.592" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_active_status_with_valid_model" time="9.247" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_failed_status_with_missing_model" time="8.787" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_authpolicy_active_status_with_valid_model" time="8.808" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_authpolicy_failed_status_with_missing_model" time="8.765" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_degraded_status_with_partial_models" time="9.132" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_authpolicy_degraded_status_with_partial_models" time="8.777" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_status_transitions_on_model_deletion" time="22.296" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_single_subscription_auto_select" time="40.016" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_explicit_subscription_header" time="16.755" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_empty_subscription_header_value" time="8.425" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_models_filtered_by_subscription" time="8.804" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_deduplication_same_model_multiple_refs" time="17.093" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_different_modelrefs_same_model_id" time="17.146" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_multiple_distinct_models_in_subscription" time="17.222" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_user_token_returns_all_models" time="16.512" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_user_token_with_subscription_header_filters" time="17.076" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_empty_model_list" time="8.738" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_response_schema_matches_openapi" time="8.419" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_model_metadata_preserved" time="8.404" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_scoped_to_subscription" time="17.090" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_with_deleted_subscription_403" time="25.100" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_with_inaccessible_subscription_403" time="17.398" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_invalid_subscription_header_403" time="17.067" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_access_denied_to_subscription_403" time="17.725" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_ignores_subscription_header" time="25.821" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_multiple_api_keys_different_subscriptions" time="25.856" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_service_account_token_multiple_subs_no_header" time="16.562" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_service_account_token_multiple_subs_with_header" time="16.540" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_unauthenticated_request_401" time="0.026" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_central_models_endpoint_exempt_from_rate_limiting" time="25.265" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelDiscovery" name="test_maasmodelref_created" time="7.301" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_httproute" time="0.117" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_backend_service" time="0.110" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelAuth" name="test_invalid_key_returns_401" time="0.026" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelAuth" name="test_no_key_returns_401" time="0.025" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelEgress" name="test_request_forwarded_returns_200" time="0.042" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelCleanup" name="test_delete_removes_httproute" time="37.590" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenFlow" name="test_oidc_token_can_create_api_key" time="20.308" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenFlow" name="test_invalid_oidc_token_gets_401" time="0.174" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenFlow" name="test_empty_bearer_token_gets_401" time="0.027" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenFlow" name="test_no_auth_header_gets_401" time="0.022" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenClaims" name="test_token_contains_groups_claim" time="0.121" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenClaims" name="test_token_contains_preferred_username" time="0.133" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenClaims" name="test_different_users_have_different_groups" time="0.272" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCMultiUser" name="test_bob_sre_can_mint_api_key" time="25.310" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCMultiUser" name="test_wrong_password_gets_rejected" time="0.123" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCMultiUser" name="test_nonexistent_user_gets_rejected" time="0.119" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCModelAccess" name="test_minted_api_key_can_list_models_and_infer" time="25.328"><failure message="AssertionError: OIDC API key mint failed: 500 {&quot;error&quot;:&quot;Exception thrown while generating token&quot;,&quot;exceptionCode&quot;:&quot;AUTH_FAILURE&quot;,&quot;refId&quot;:&quot;003&quot;}&#10;assert 500 in (200, 201)&#10; +  where 500 = &lt;Response [500]&gt;.status_code">self = &lt;test_external_oidc.TestOIDCModelAccess object at 0x7f3a570a7580&gt;
maas_api_base_url = 'https://maas.apps.04faa770-22fb-475a-b4e9-f5a176fc4161.prod.konfluxeaas.com/maas-api'

    def test_minted_api_key_can_list_models_and_infer(self, maas_api_base_url: str):
        """Complete happy path: OIDC token → API key → model list → inference."""
        token = _request_oidc_token()
&gt;       api_key = _create_oidc_api_key(maas_api_base_url, token)["key"]

test/e2e/tests/test_external_oidc.py:362: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

maas_api_base_url = 'https://maas.apps.04faa770-22fb-475a-b4e9-f5a176fc4161.prod.konfluxeaas.com/maas-api'
oidc_token = 'eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJFcnBNRklKVjJtU2RoYVNoenFzdzlwdWF5YlRFWXpCbzNFRzl1cVpzS3pRIn0.eyJle...dV4Bp0rzcWMB2dckbaZa0Ma9BeUty2SXOzNh9sNYq97XqhvEeACWfQ6mwU8GxGiU8q4urSvp37lLqRjL2cDCyvVJ1Ten5iXu7G8EvtLYdyXEoeSBH-Lmyg'
name = None, subscription = None

    def _create_oidc_api_key(
        maas_api_base_url: str,
        oidc_token: str,
        name: str | None = None,
        subscription: str | None = None,
    ) -&gt; dict:
        """Mint a MaaS API key using an OIDC bearer token.
    
        Retries on empty 403 (gateway propagation delay) and 401 (Authorino
        may still be loading the OIDC JWKS keys from Keycloak).
    
        Args:
            maas_api_base_url: MaaS API base URL
            oidc_token: OIDC access token
            name: Optional key name (auto-generated if omitted)
            subscription: Optional subscription to bind at mint time
    
        Returns:
            Full response body dict (includes 'key', 'id', 'subscription', etc.)
        """
        body: dict = {"name": name or f"e2e-oidc-{uuid.uuid4().hex[:8]}"}
        if subscription:
            body["subscription"] = subscription
    
        retries, delay = 6, 5
        for attempt in range(1, retries + 1):
            response = requests.post(
                f"{maas_api_base_url}/v1/api-keys",
                headers={"Authorization": f"Bearer {oidc_token}", "Content-Type": "application/json"},
                json=body,
                timeout=30,
                verify=TLS_VERIFY,
            )
            # Empty 403: gateway hasn't loaded AuthPolicy yet
            # 401: Authorino may still be fetching OIDC JWKS keys
            # 500 AUTH_FAILURE: Authorino validated the JWT but response header
            #   CEL expression hasn't stabilized (X-MaaS-Username empty)
            if (response.status_code == 403 and not response.text.strip()) \
                    or response.status_code == 401 \
                    or (response.status_code == 500 and "AUTH_FAILURE" in response.text):
                if attempt &lt; retries:
                    log.info("OIDC API key mint got %d (attempt %d/%d), retrying in %ds...",
                             response.status_code, attempt, retries, delay)
                    time.sleep(delay)
                    continue
            break
    
&gt;       assert response.status_code in (200, 201), (
            f"OIDC API key mint failed: {response.status_code} {response.text}"
        )
E       AssertionError: OIDC API key mint failed: 500 {"error":"Exception thrown while generating token","exceptionCode":"AUTH_FAILURE","refId":"003"}
E       assert 500 in (200, 201)
E        +  where 500 = &lt;Response [500]&gt;.status_code

test/e2e/tests/test_external_oidc.py:195: AssertionError</failure></testcase><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCModelAccess" name="test_revoked_api_key_cannot_access_models" time="13.288" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCMultiTenant" name="test_tenant_b_token_rejected_by_maas" time="0.198" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCMultiTenant" name="test_tenant_a_users_are_isolated" time="30.548"><failure message="AssertionError: OIDC API key mint failed: 500 {&quot;error&quot;:&quot;Exception thrown while generating token&quot;,&quot;exceptionCode&quot;:&quot;AUTH_FAILURE&quot;,&quot;refId&quot;:&quot;003&quot;}&#10;assert 500 in (200, 201)&#10; +  where 500 = &lt;Response [500]&gt;.status_code">self = &lt;test_external_oidc.TestOIDCMultiTenant object at 0x7f3a57148f70&gt;
maas_api_base_url = 'https://maas.apps.04faa770-22fb-475a-b4e9-f5a176fc4161.prod.konfluxeaas.com/maas-api'

    def test_tenant_a_users_are_isolated(self, maas_api_base_url: str):
        """Different tenant-a users can each mint their own API keys independently."""
        alice_token = _request_oidc_token(username="alice_lead", password="letmein")
        bob_token = _request_oidc_token(username="bob_sre", password="letmein")
    
        alice_key = _create_oidc_api_key(
            maas_api_base_url, alice_token, name=f"e2e-alice-iso-{uuid.uuid4().hex[:8]}"
        )
&gt;       bob_key = _create_oidc_api_key(
            maas_api_base_url, bob_token, name=f"e2e-bob-iso-{uuid.uuid4().hex[:8]}"
        )

test/e2e/tests/test_external_oidc.py:488: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

maas_api_base_url = 'https://maas.apps.04faa770-22fb-475a-b4e9-f5a176fc4161.prod.konfluxeaas.com/maas-api'
oidc_token = 'eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJFcnBNRklKVjJtU2RoYVNoenFzdzlwdWF5YlRFWXpCbzNFRzl1cVpzS3pRIn0.eyJle...hjMYQmxZPswnffoNTQamcGEKxVw2Rmq5m45eYDbijieeq35hNdm8JP_xmd9kAolIdB8UjbGmR-2vLF59ur_NixQbyRom7ChydDNZrr-4vy3csrG2jQDaWg'
name = 'e2e-bob-iso-f5e1ba4c', subscription = None

    def _create_oidc_api_key(
        maas_api_base_url: str,
        oidc_token: str,
        name: str | None = None,
        subscription: str | None = None,
    ) -&gt; dict:
        """Mint a MaaS API key using an OIDC bearer token.
    
        Retries on empty 403 (gateway propagation delay) and 401 (Authorino
        may still be loading the OIDC JWKS keys from Keycloak).
    
        Args:
            maas_api_base_url: MaaS API base URL
            oidc_token: OIDC access token
            name: Optional key name (auto-generated if omitted)
            subscription: Optional subscription to bind at mint time
    
        Returns:
            Full response body dict (includes 'key', 'id', 'subscription', etc.)
        """
        body: dict = {"name": name or f"e2e-oidc-{uuid.uuid4().hex[:8]}"}
        if subscription:
            body["subscription"] = subscription
    
        retries, delay = 6, 5
        for attempt in range(1, retries + 1):
            response = requests.post(
                f"{maas_api_base_url}/v1/api-keys",
                headers={"Authorization": f"Bearer {oidc_token}", "Content-Type": "application/json"},
                json=body,
                timeout=30,
                verify=TLS_VERIFY,
            )
            # Empty 403: gateway hasn't loaded AuthPolicy yet
            # 401: Authorino may still be fetching OIDC JWKS keys
            # 500 AUTH_FAILURE: Authorino validated the JWT but response header
            #   CEL expression hasn't stabilized (X-MaaS-Username empty)
            if (response.status_code == 403 and not response.text.strip()) \
                    or response.status_code == 401 \
                    or (response.status_code == 500 and "AUTH_FAILURE" in response.text):
                if attempt &lt; retries:
                    log.info("OIDC API key mint got %d (attempt %d/%d), retrying in %ds...",
                             response.status_code, attempt, retries, delay)
                    time.sleep(delay)
                    continue
            break
    
&gt;       assert response.status_code in (200, 201), (
            f"OIDC API key mint failed: {response.status_code} {response.text}"
        )
E       AssertionError: OIDC API key mint failed: 500 {"error":"Exception thrown while generating token","exceptionCode":"AUTH_FAILURE","refId":"003"}
E       assert 500 in (200, 201)
E        +  where 500 = &lt;Response [500]&gt;.status_code

test/e2e/tests/test_external_oidc.py:195: AssertionError</failure></testcase><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCAPIKeyLifecycle" name="test_create_and_revoke_api_key" time="0.188"><failure message="AssertionError: API key revocation failed: 500 {&quot;error&quot;:&quot;Exception thrown while generating token&quot;,&quot;exceptionCode&quot;:&quot;AUTH_FAILURE&quot;,&quot;refId&quot;:&quot;003&quot;}&#10;assert 500 in (200, 204)&#10; +  where 500 = &lt;Response [500]&gt;.status_code">self = &lt;test_external_oidc.TestOIDCAPIKeyLifecycle object at 0x7f3a57148fd0&gt;
maas_api_base_url = 'https://maas.apps.04faa770-22fb-475a-b4e9-f5a176fc4161.prod.konfluxeaas.com/maas-api'

    def test_create_and_revoke_api_key(self, maas_api_base_url: str):
        """Full create → revoke lifecycle with OIDC token."""
        token = _request_oidc_token()
    
        # Create
        key_data = _create_oidc_api_key(maas_api_base_url, token, name=f"e2e-revoke-{uuid.uuid4().hex[:8]}")
        key_id = key_data["id"]
    
        # Revoke
        response = requests.delete(
            f"{maas_api_base_url}/v1/api-keys/{key_id}",
            headers={"Authorization": f"Bearer {token}", "Content-Type": "application/json"},
            timeout=30,
            verify=TLS_VERIFY,
        )
&gt;       assert response.status_code in (200, 204), (
            f"API key revocation failed: {response.status_code} {response.text}"
        )
E       AssertionError: API key revocation failed: 500 {"error":"Exception thrown while generating token","exceptionCode":"AUTH_FAILURE","refId":"003"}
E       assert 500 in (200, 204)
E        +  where 500 = &lt;Response [500]&gt;.status_code

test/e2e/tests/test_external_oidc.py:521: AssertionError</failure></testcase><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_username_header_ignored" time="5.236" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_group_header_does_not_escalate" time="25.416" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_subscription_header_ignored" time="0.222" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_username_on_oidc_token_ignored" time="15.254" /></testsuite></testsuites>