<?xml version="1.0" encoding="utf-8"?><testsuites name="pytest tests"><testsuite name="pytest" errors="0" failures="5" skipped="24" tests="180" time="1692.286" timestamp="2026-06-11T23:26:39.683090+00:00" hostname="maas-group-test-t9h6s-e2e-maas-openshift-pod"><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyCRUD" name="test_create_api_key" time="0.119" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyCRUD" name="test_list_api_keys" time="0.154" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyCRUD" name="test_revoke_api_key" time="0.112" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyAuthorization" name="test_admin_manage_other_users_keys" time="0.153" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyAuthorization" name="test_non_admin_cannot_access_other_users_keys" time="0.106" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_own_keys" time="0.300" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_other_user_forbidden" time="0.036" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_admin_can_revoke_any_user" time="0.104" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_within_expiration_limit" time="0.036" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_at_expiration_limit" time="0.037" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_exceeds_expiration_limit" time="0.035" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_without_expiration" time="0.036" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_with_short_expiration" time="0.039" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_api_key_model_access_success" time="0.136" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_invalid_api_key_rejected" time="0.025" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_no_auth_header_rejected" time="0.021" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_revoked_api_key_rejected" time="2.137" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_api_key_chat_completions" time="0.034" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_double_revoke_returns_404" time="0.112" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_nonexistent_key_returns_404" time="0.033" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_then_create_new_key_works" time="0.170" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_individual_revoke_multiple_keys" time="0.218" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_keys_rejected_at_gateway" time="0.331" /><testcase classname="test.e2e.tests.test_api_keys.TestEphemeralKeyCleanup" name="test_cronjob_exists_and_configured" time="0.114" /><testcase classname="test.e2e.tests.test_api_keys.TestEphemeralKeyCleanup" name="test_cleanup_networkpolicy_exists" time="0.115" /><testcase classname="test.e2e.tests.test_api_keys.TestEphemeralKeyCleanup" name="test_create_ephemeral_key" time="0.122" /><testcase classname="test.e2e.tests.test_api_keys.TestEphemeralKeyCleanup" name="test_trigger_cleanup_preserves_active_keys" time="0.542" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_active_subscription" time="13.568" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_degraded_subscription" time="19.180" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_failed_subscription" time="19.391" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_pending_subscription" time="19.342" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_reject_key_for_unreconciled_subscription" time="22.504" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionFilter" name="test_search_filters_by_subscription" time="14.690" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionFilter" name="test_search_without_subscription_returns_all" time="0.204" /><testcase classname="test.e2e.tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_subscription_namespace_visible_to_api" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:212: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="test.e2e.tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_another_namespace_not_visible_to_api" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:245: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="test.e2e.tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_maas_subscription_namespace" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:283: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="test.e2e.tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_another_namespace" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:321: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="test.e2e.tests.test_namespace_scoping.TestModelRef" name="test_auth_policy_model_ref" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:378: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="test.e2e.tests.test_namespace_scoping.TestModelRef" name="test_subscription_model_ref" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:454: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="test.e2e.tests.test_negative_security.TestHeaderSpoofing" name="test_injected_identity_headers_ignored" time="0.088" /><testcase classname="test.e2e.tests.test_negative_security.TestHeaderSpoofing" name="test_duplicate_subscription_headers_ignored" time="0.068" /><testcase classname="test.e2e.tests.test_negative_security.TestExpiredKeyRejection" name="test_expired_key_rejected_at_gateway" time="5.076" /><testcase classname="test.e2e.tests.test_negative_security.TestCrossModelAccess" name="test_key_cannot_access_model_outside_subscription" time="0.067" /><testcase classname="test.e2e.tests.test_negative_security.TestAuthPolicyRemoval" name="test_authpolicy_deletion_revokes_access" time="0.820" /><testcase classname="test.e2e.tests.test_negative_security.TestMissingModelRef" name="test_subscription_with_nonexistent_model_ref" time="1.044" /><testcase classname="test.e2e.tests.test_negative_security.TestMissingModelRef" name="test_authpolicy_with_nonexistent_model_ref" time="0.670" /><testcase classname="test.e2e.tests.test_negative_security.TestHeaderAbuse" name="test_special_characters_in_subscription_header" time="0.180" /><testcase classname="test.e2e.tests.test_negative_security.TestWebhookValidation" name="test_subscription_rejected_in_unlabeled_namespace" time="6.429" /><testcase classname="test.e2e.tests.test_negative_security.TestWebhookValidation" name="test_authpolicy_rejected_in_unlabeled_namespace" time="6.001" /><testcase classname="test.e2e.tests.test_subscription.TestAuthEnforcement" name="test_authorized_user_gets_200" time="0.089" /><testcase classname="test.e2e.tests.test_subscription.TestAuthEnforcement" name="test_no_auth_gets_401" time="0.025" /><testcase classname="test.e2e.tests.test_subscription.TestAuthEnforcement" name="test_invalid_token_gets_403" time="0.047" /><testcase classname="test.e2e.tests.test_subscription.TestAuthEnforcement" name="test_wrong_group_gets_403" time="0.033" /><testcase classname="test.e2e.tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_uses_highest_priority_subscription" time="0.326" /><testcase classname="test.e2e.tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_with_explicit_simulator_subscription" time="0.072" /><testcase classname="test.e2e.tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_nonexistent_subscription_errors" time="0.261" /><testcase classname="test.e2e.tests.test_subscription.TestSubscriptionEnforcement" name="test_subscribed_user_gets_200" time="0.041" /><testcase classname="test.e2e.tests.test_subscription.TestSubscriptionEnforcement" name="test_auth_pass_no_subscription_gets_403" time="16.431" /><testcase classname="test.e2e.tests.test_subscription.TestSubscriptionEnforcement" name="test_rate_limit_exhaustion_gets_429" time="25.609" /><testcase classname="test.e2e.tests.test_subscription.TestSubscriptionEnforcement" name="test_models_endpoint_exempt_from_rate_limiting" time="25.283" /><testcase classname="test.e2e.tests.test_subscription.TestMultipleSubscriptionsPerModel" name="test_user_in_one_of_two_subscriptions_gets_200" time="8.390" /><testcase classname="test.e2e.tests.test_subscription.TestMultipleAuthPoliciesPerModel" name="test_two_auth_policies_or_logic" time="16.797" /><testcase classname="test.e2e.tests.test_subscription.TestMultipleAuthPoliciesPerModel" name="test_delete_one_auth_policy_other_still_works" time="24.532" /><testcase classname="test.e2e.tests.test_subscription.TestCascadeDeletion" name="test_delete_subscription_rebuilds_trlp" time="8.533" /><testcase classname="test.e2e.tests.test_subscription.TestCascadeDeletion" name="test_trlp_persists_during_multi_subscription_deletion" time="33.351" /><testcase classname="test.e2e.tests.test_subscription.TestCascadeDeletion" name="test_delete_last_subscription_denies_access" time="8.610" /><testcase classname="test.e2e.tests.test_subscription.TestCascadeDeletion" name="test_unconfigured_model_denied_by_gateway_auth" time="0.484" /><testcase classname="test.e2e.tests.test_subscription.TestOrderingEdgeCases" name="test_subscription_before_auth_policy" time="27.749" /><testcase classname="test.e2e.tests.test_subscription.TestManagedAnnotation" name="test_authpolicy_managed_false_prevents_update" time="8.257"><skipped type="pytest.skip" message="gateway-only mode: per-model AuthPolicy is not created">/workspace/source/test/e2e/tests/test_subscription.py:1040: gateway-only mode: per-model AuthPolicy is not created</skipped></testcase><testcase classname="test.e2e.tests.test_subscription.TestManagedAnnotation" name="test_trlp_managed_false_prevents_update" time="20.760" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_both_access_and_subscription_gets_200" time="9.689" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_access_but_no_subscription_gets_403" time="17.196" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_subscription_but_no_access_gets_403" time="9.673" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_single_subscription_auto_selects" time="17.572" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_multiple_subscriptions_separate_keys_gets_200" time="17.526" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_mint_api_key_denied_for_inaccessible_subscription" time="17.752" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_access_gets_200" time="17.129" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_auth_but_no_subscription_gets_403" time="17.209" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_subscription_but_no_auth_gets_403" time="9.347" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_active_status_with_valid_model" time="9.294" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_failed_status_with_missing_model" time="8.783" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_authpolicy_active_status_with_valid_model" time="8.773" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_authpolicy_failed_status_with_missing_model" time="8.793" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_degraded_status_with_partial_models" time="9.133" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_degraded_trlp_blocks_inference" time="86.968"><failure message="AssertionError: Expected 403 Forbidden for Degraded subscription with TRLP not ready, got 503: no healthy upstream&#10;assert 503 == 403&#10; +  where 503 = &lt;Response [503]&gt;.status_code">self = &lt;test_subscription.TestStatusReporting object at 0x7f3393141130&gt;

    def test_subscription_degraded_trlp_blocks_inference(self):
        """
        Test: Degraded subscription with TRLP not ready blocks inference.
    
        This test verifies that when a subscription enters Degraded phase due to
        TokenRateLimitPolicy not being ready (e.g., Kuadrant controller down),
        inference requests are blocked with appropriate error to prevent rate
        limits from being bypassed.
    
        Uses pre-deployed e2e-trlp-test-simulated model to avoid TRLP sharing with concurrent tests.
    
        Test flow:
        1. Scale down Kuadrant controller
        2. Create subscription with valid model - TRLP created but not accepted
        3. Wait for subscription to enter Degraded phase (TRLP ready=false)
        4. Create API key and verify inference is blocked (403 Forbidden)
        5. Scale Kuadrant controller back up
        6. Wait for subscription to reach Active phase (TRLP ready=true)
        7. Verify inference works (200 OK)
        """
        ns = _ns()
        subscription_name = "e2e-trlp-degraded-sub"
        auth_name = "e2e-trlp-degraded-auth"
        sa_name = "e2e-trlp-degraded-sa"
    
        try:
            # Step 1: Scale down Kuadrant controller BEFORE creating subscription
            log.info("Step 1: Scaling down Kuadrant controller...")
            _scale_kuadrant_controller_down()
            time.sleep(5)  # Give time for controller to fully stop
    
            # Step 2: Create auth policy and subscription
            log.info("Step 2: Creating subscription with Kuadrant controller down...")
            sa_token = _create_sa_token(sa_name, namespace=MODEL_NAMESPACE)
            sa_user = _sa_to_user(sa_name, namespace=MODEL_NAMESPACE)
    
            _create_test_auth_policy(auth_name, TRLP_TEST_MODEL_REF, users=[sa_user])
            _create_test_subscription(subscription_name, TRLP_TEST_MODEL_REF, users=[sa_user])
    
            # Wait for auth policy to reconcile. In gateway-only mode, it remains Active even when
            # Kuadrant TRLP reconciliation is degraded.
            log.info("Waiting for MaaSAuthPolicy to reconcile...")
            _wait_for_maas_auth_policy_phase(auth_name, "Active", timeout=60, require_auth_policies=False)
    
            # Step 3: Wait for subscription to reach Degraded phase with TRLP not ready
            log.info("Step 3: Waiting for subscription to enter Degraded phase (TRLP not ready)...")
            cr = _wait_for_maas_subscription_phase(subscription_name, "Degraded", timeout=120)
            _wait_for_subscription_trlp_status(subscription_name, expected_ready=False, timeout=120)
    
            status = cr.get("status", {})
            trlp_statuses = status.get("tokenRateLimitStatuses", [])
            log.info(f"Subscription Degraded: phase={status.get('phase')}, trlpStatuses={trlp_statuses}")
    
            # Verify at least one TRLP is not ready
            assert len(trlp_statuses) &gt; 0, "Expected at least one TRLP status"
            assert any(not trlp.get("ready") for trlp in trlp_statuses), "Expected at least one TRLP to be not ready"
            log.info("✅ Subscription in Degraded phase with TRLP not ready")
    
            # Step 4: Create API key and verify inference is blocked
            log.info("Step 4: Creating API key and verifying inference is blocked...")
            api_key = _create_api_key(sa_token, name="e2e-trlp-test-key", subscription=subscription_name)
    
            resp = _inference(api_key, path=TRLP_TEST_MODEL_PATH, model_name=TRLP_TEST_MODEL_ID)
&gt;           assert resp.status_code == 403, f"Expected 403 Forbidden for Degraded subscription with TRLP not ready, got {resp.status_code}: {resp.text}"
E           AssertionError: Expected 403 Forbidden for Degraded subscription with TRLP not ready, got 503: no healthy upstream
E           assert 503 == 403
E            +  where 503 = &lt;Response [503]&gt;.status_code

test/e2e/tests/test_subscription.py:1993: AssertionError</failure></testcase><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_authpolicy_degraded_status_with_partial_models" time="8.810" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_status_transitions_on_model_deletion" time="22.279" /><testcase classname="test.e2e.tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_degraded_healthy_model_allows_inference" time="19.287" /><testcase classname="test.e2e.tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_failed_subscription_blocks_inference" time="19.590" /><testcase classname="test.e2e.tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_models_endpoint_with_degraded_subscription_api_key" time="19.338" /><testcase classname="test.e2e.tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_models_endpoint_with_degraded_subscription_kube_token" time="19.265" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_single_subscription_auto_select" time="42.286" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_explicit_subscription_header" time="16.800" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_empty_subscription_header_value" time="8.445" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_models_filtered_by_subscription" time="8.899" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_deduplication_same_model_multiple_refs" time="17.285" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_different_modelrefs_same_model_id" time="17.334" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_multiple_distinct_models_in_subscription" time="21.524" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_user_token_returns_all_models" time="14.579" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_user_token_with_subscription_header_filters" time="17.149" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_empty_model_list" time="11.100" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_response_schema_matches_openapi" time="8.431" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_model_metadata_preserved" time="8.452" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_scoped_to_subscription" time="17.226" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_with_deleted_subscription_403" time="25.269" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_with_inaccessible_subscription_403" time="17.472" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_invalid_subscription_header_403" time="17.059" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_access_denied_to_subscription_403" time="17.750" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_ignores_subscription_header" time="22.273" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_multiple_api_keys_different_subscriptions" time="22.442" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_service_account_token_multiple_subs_no_header" time="12.348" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_service_account_token_multiple_subs_with_header" time="14.502" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_unauthenticated_request_401" time="0.024" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_central_models_endpoint_exempt_from_rate_limiting" time="25.678" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelDiscovery" name="test_maasmodelref_created" time="3.130" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_httproute" time="0.112" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_backend_service" time="0.115" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelAuth" name="test_invalid_key_returns_401" time="0.046" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelAuth" name="test_no_key_returns_401" time="0.023" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelEgress" name="test_request_forwarded_returns_200" time="0.034" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelCleanup" name="test_delete_removes_httproute" time="37.607" /><testcase classname="test.e2e.tests.test_tenant.TestTenantLifecycle" name="test_tenant_ready_and_phase_healthy" time="0.351" /><testcase classname="test.e2e.tests.test_tenant.TestTenantLifecycle" name="test_payload_processing_deployed_with_active_tenant" time="0.115"><skipped type="pytest.skip" message="Tenant not Active (e.g. Degraded); payload-processing not asserted">/workspace/source/test/e2e/tests/test_tenant.py:127: Tenant not Active (e.g. Degraded); payload-processing not asserted</skipped></testcase><testcase classname="test.e2e.tests.test_tenant.TestTenantContract" name="test_status_has_phase_and_conditions" time="0.119" /><testcase classname="test.e2e.tests.test_tenant.TestTenantContract" name="test_spec_is_well_formed" time="0.116" /><testcase classname="test.e2e.tests.test_tenant.TestTenantContract" name="test_conditions_use_kubernetes_metav1_shape" time="0.107" /><testcase classname="test.e2e.tests.test_tenant.TestTenantNoFalseOwnership" name="test_maas_user_crs_not_owned_by_tenant" time="0.354" /><testcase classname="test.e2e.tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_create_bootstrap_resources" time="12.725" /><testcase classname="test.e2e.tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_delete_cleans_up_bootstrap_resources" time="13.596" /><testcase classname="test.e2e.tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_rejects_models_as_a_service_for_non_default_tenant" time="0.796" /><testcase classname="test.e2e.tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_labeled_tenant_namespace_is_discovered" time="7.883" /><testcase classname="test.e2e.tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_label_removal_stops_reconciliation" time="33.196" /><testcase classname="test.e2e.tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_unlabeled_namespace_ignored" time="21.899" /><testcase classname="test.e2e.tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_dynamic_discovery_after_label_added" time="17.650" /><testcase classname="test.e2e.tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_per_tenant_oidc_configuration" time="7.173" /><testcase classname="test.e2e.tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_namespace_qualified_collision_prevention" time="15.596" /><testcase classname="test.e2e.tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_tenant_admin_rbac_is_namespace_scoped" time="19.551" /><testcase classname="test.e2e.tests.test_tenant_namespace_discovery.TestTenantWebhookValidation" name="test_maassubscription_rejected_without_tenant_cr" time="6.409" /><testcase classname="test.e2e.tests.test_tenant_namespace_discovery.TestTenantWebhookValidation" name="test_maasauthpolicy_rejected_without_tenant_cr" time="6.051" /><testcase classname="test.e2e.tests.test_tenant_namespace_discovery.TestTenantDiscoveryDormantMode" name="test_dormant_mode_ignores_labeled_namespace" time="0.000"><skipped type="pytest.skip" message="Dormant-mode test mutates controller flags; set ENABLE_TENANT_DISCOVERY_DORMANT_E2E=true">/workspace/source/test/e2e/tests/test_tenant_namespace_discovery.py:358: Dormant-mode test mutates controller flags; set ENABLE_TENANT_DISCOVERY_DORMANT_E2E=true</skipped></testcase><testcase classname="test.e2e.tests.test_tenant_namespace_discovery.TestLegacyDefaultNamespaceStillWorks" name="test_models_as_a_service_namespace_reconciles" time="0.572" /><testcase classname="test.e2e.tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyStructure" name="test_target_ref_points_to_gateway" time="0.247" /><testcase classname="test.e2e.tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyStructure" name="test_no_per_model_authpolicy_for_fixture_model" time="0.119" /><testcase classname="test.e2e.tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyLifecycle" name="test_gateway_auth_embeds_model_allowlist" time="8.721" /><testcase classname="test.e2e.tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyLifecycle" name="test_only_one_gateway_authpolicy_named_maas_gateway_auth" time="0.237" /><testcase classname="test.e2e.tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_full_tenant_lifecycle_create_to_delete" time="136.969"><failure message="AssertionError: maassubscription/e2e-sub-aecf84b0 in e2e-mt-aecf84b0 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{&quot;apiVersion&quot;:&quot;maas.opendatahub.io/v1alpha1&quot;,&quot;kind&quot;:&quot;MaaSSubscription&quot;,&quot;metadata&quot;:{&quot;annotations&quot;:{},&quot;name&quot;:&quot;e2e-sub-aecf84b0&quot;,&quot;namespace&quot;:&quot;e2e-mt-aecf84b0&quot;},&quot;spec&quot;:{&quot;modelRefs&quot;:[{&quot;name&quot;:&quot;facebook-opt-125m-simulated&quot;,&quot;namespace&quot;:&quot;llm&quot;,&quot;tokenRateLimits&quot;:[{&quot;limit&quot;:100,&quot;window&quot;:&quot;1m&quot;}]}],&quot;owner&quot;:{&quot;groups&quot;:[{&quot;name&quot;:&quot;system:authenticated&quot;}]}}}\n'}, 'creationTimestamp': '2026-06-11T23:49:00Z', 'finalizers': ['maas.opendatahub.io/subscription-cleanup'], 'generation': 1, 'name': 'e2e-sub-aecf84b0', 'namespace': 'e2e-mt-aecf84b0', 'resourceVersion': '52139', 'uid': '98443d1e-bb95-4cbb-837a-fb11f3a74c04'}, 'spec': {'modelRefs': [{'name': 'facebook-opt-125m-simulated', 'namespace': 'llm', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-06-11T23:49:00Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}, {'lastTransitionTime': '2026-06-11T23:49:00Z', 'message': 'failed to reconcile TokenRateLimitPolicies: model llm/facebook-opt-125m-simulated is not attached to tenant gateway for subscription e2e-mt-aecf84b0/e2e-sub-aecf84b0: HTTPRoute llm/facebook-opt-125m-simulated-kserve-route does not reference tenant Gateway openshift-ingress/e2e-mt-aecf84b0', 'observedGeneration': 1, 'reason': 'ReconcileFailed', 'status': 'False', 'type': 'Ready'}], 'modelRefStatuses': [{'name': 'facebook-opt-125m-simulated', 'namespace': 'llm', 'ready': True, 'reason': 'Valid'}], 'phase': 'Failed'}}">self = &lt;test_multi_tenant_integration.TestMultiTenantIntegration object at 0x7f33930dc760&gt;

    def test_full_tenant_lifecycle_create_to_delete(self):
        """7.1: Full tenant lifecycle from create through policy/subscription reconcile to delete."""
        case = new_discovery_case()
        role_name = f"aitenant-{case['tenant_label_name']}-tenant-admin"
        try:
            apply_gateway_fixture(case["gateway_name"], fixture_label=case["tenant_label_name"])
            bootstrap_aitenant_tenant(case)
    
            tenant = wait_for_json("tenant", TENANT_CR_NAME, case["tenant_ns"], timeout=180)
            assert tenant["spec"]["gatewayRef"]["name"] == case["gateway_name"]
            assert get_json_or_none("role", role_name, case["tenant_ns"]) is not None
    
            apply_maas_auth_policy(case["policy_name"], case["tenant_ns"])
            apply_maas_subscription(case["subscription_name"], case["tenant_ns"])
            wait_for_status_phase("maasauthpolicy", case["policy_name"], case["tenant_ns"], expected_phase="Active")
&gt;           wait_for_status_phase(
                "maassubscription",
                case["subscription_name"],
                case["tenant_ns"],
                expected_phase=("Active", "Degraded"),
            )

test/e2e/tests/test_multi_tenant_integration.py:77: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/multitenancy_helpers.py:253: in wait_for_status_phase
    return wait_for_json(kind, name, namespace, predicate=_predicate, timeout=timeout, interval=interval)
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'maassubscription', name = 'e2e-sub-aecf84b0'
namespace = 'e2e-mt-aecf84b0'

    def wait_for_json(
        kind: str,
        name: str,
        namespace: Optional[str] = None,
        *,
        predicate=None,
        timeout: int = 180,
        interval: int = 5,
    ) -&gt; dict:
        deadline = time.time() + timeout
        last_obj = None
        while time.time() &lt; deadline:
            obj = get_json_or_none(kind, name, namespace)
            if obj is not None:
                last_obj = obj
                if predicate is None or predicate(obj):
                    return obj
            time.sleep(interval)
&gt;       raise AssertionError(
            f"{kind}/{name} in {namespace or '&lt;cluster&gt;'} did not satisfy condition. Last object: {last_obj}"
        )
E       AssertionError: maassubscription/e2e-sub-aecf84b0 in e2e-mt-aecf84b0 did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'MaaSSubscription', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{"apiVersion":"maas.opendatahub.io/v1alpha1","kind":"MaaSSubscription","metadata":{"annotations":{},"name":"e2e-sub-aecf84b0","namespace":"e2e-mt-aecf84b0"},"spec":{"modelRefs":[{"name":"facebook-opt-125m-simulated","namespace":"llm","tokenRateLimits":[{"limit":100,"window":"1m"}]}],"owner":{"groups":[{"name":"system:authenticated"}]}}}\n'}, 'creationTimestamp': '2026-06-11T23:49:00Z', 'finalizers': ['maas.opendatahub.io/subscription-cleanup'], 'generation': 1, 'name': 'e2e-sub-aecf84b0', 'namespace': 'e2e-mt-aecf84b0', 'resourceVersion': '52139', 'uid': '98443d1e-bb95-4cbb-837a-fb11f3a74c04'}, 'spec': {'modelRefs': [{'name': 'facebook-opt-125m-simulated', 'namespace': 'llm', 'tokenRateLimits': [{'limit': 100, 'window': '1m'}]}], 'owner': {'groups': [{'name': 'system:authenticated'}]}, 'priority': 0}, 'status': {'conditions': [{'lastTransitionTime': '2026-06-11T23:49:00Z', 'message': '', 'observedGeneration': 1, 'reason': 'NoDuplicatePeers', 'status': 'False', 'type': 'SpecPriorityDuplicate'}, {'lastTransitionTime': '2026-06-11T23:49:00Z', 'message': 'failed to reconcile TokenRateLimitPolicies: model llm/facebook-opt-125m-simulated is not attached to tenant gateway for subscription e2e-mt-aecf84b0/e2e-sub-aecf84b0: HTTPRoute llm/facebook-opt-125m-simulated-kserve-route does not reference tenant Gateway openshift-ingress/e2e-mt-aecf84b0', 'observedGeneration': 1, 'reason': 'ReconcileFailed', 'status': 'False', 'type': 'Ready'}], 'modelRefStatuses': [{'name': 'facebook-opt-125m-simulated', 'namespace': 'llm', 'ready': True, 'reason': 'Valid'}], 'phase': 'Failed'}}

test/e2e/tests/multitenancy_helpers.py:198: AssertionError</failure></testcase><testcase classname="test.e2e.tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_default_tenant_unaffected_by_multitenancy_enablement" time="0.939" /><testcase classname="test.e2e.tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_same_named_resources_across_tenants" time="14.888" /><testcase classname="test.e2e.tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_tenant_namespace_label_change_triggers_reconciliation" time="37.794" /><testcase classname="test.e2e.tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_aitenant_creates_dedicated_maas_api_infrastructure" time="0.000"><skipped type="pytest.skip" message="S24 per-tenant maas-api E2E is gated; set ENABLE_S24_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_multi_tenant_maas_api.py:68: S24 per-tenant maas-api E2E is gated; set ENABLE_S24_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_tenant_name_environment_variable_set" time="0.000"><skipped type="pytest.skip" message="S24 per-tenant maas-api E2E is gated; set ENABLE_S24_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_multi_tenant_maas_api.py:87: S24 per-tenant maas-api E2E is gated; set ENABLE_S24_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_service_routing_isolation" time="0.000"><skipped type="pytest.skip" message="S24 per-tenant maas-api E2E is gated; set ENABLE_S24_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_multi_tenant_maas_api.py:96: S24 per-tenant maas-api E2E is gated; set ENABLE_S24_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_httproute_tenant_attachment" time="0.000"><skipped type="pytest.skip" message="S24 per-tenant maas-api E2E is gated; set ENABLE_S24_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_multi_tenant_maas_api.py:113: S24 per-tenant maas-api E2E is gated; set ENABLE_S24_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_default_and_multiple_tenants_coexist" time="0.000"><skipped type="pytest.skip" message="S24 per-tenant maas-api E2E is gated; set ENABLE_S24_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_multi_tenant_maas_api.py:124: S24 per-tenant maas-api E2E is gated; set ENABLE_S24_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_creation_scoped_to_tenant" time="0.000"><skipped type="pytest.skip" message="S4 tenant persistence E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_tenant_auth_isolation.py:109: S4 tenant persistence E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_validates_against_correct_tenant" time="0.000"><skipped type="pytest.skip" message="S4 tenant persistence E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_tenant_auth_isolation.py:122: S4 tenant persistence E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_rejected_cross_tenant" time="0.000"><skipped type="pytest.skip" message="S4 tenant persistence E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_tenant_auth_isolation.py:130: S4 tenant persistence E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_oidc_token_validation_per_tenant" time="0.000"><skipped type="pytest.skip" message="S4 tenant persistence E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_tenant_auth_isolation.py:137: S4 tenant persistence E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_list_scoped_to_tenant" time="0.000"><skipped type="pytest.skip" message="S4 tenant persistence E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_tenant_auth_isolation.py:153: S4 tenant persistence E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_subscription_selection_uses_tenant_namespace" time="0.000"><skipped type="pytest.skip" message="S4 tenant persistence E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_tenant_auth_isolation.py:176: S4 tenant persistence E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_tenant_subscription_isolation.TestTenantSubscriptionIsolation" name="test_subscription_list_scoped_to_tenant" time="0.000"><skipped type="pytest.skip" message="S4 tenant subscription isolation E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_tenant_subscription_isolation.py:101: S4 tenant subscription isolation E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_tenant_subscription_isolation.TestTenantSubscriptionIsolation" name="test_subscription_selection_per_tenant" time="0.000"><skipped type="pytest.skip" message="S4 tenant subscription isolation E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_tenant_subscription_isolation.py:120: S4 tenant subscription isolation E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_tenant_rate_limit_isolation.TestTenantRateLimitIsolation" name="test_rate_limit_enforced_per_tenant" time="0.000"><skipped type="pytest.skip" message="S4 tenant rate-limit isolation E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_tenant_rate_limit_isolation.py:154: S4 tenant rate-limit isolation E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_tenant_rate_limit_isolation.TestTenantRateLimitIsolation" name="test_independent_tenant_rate_limits" time="0.000"><skipped type="pytest.skip" message="S4 tenant rate-limit isolation E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands">/workspace/source/test/e2e/tests/test_tenant_rate_limit_isolation.py:163: S4 tenant rate-limit isolation E2E is gated; set ENABLE_S4_E2E=true once the backing implementation lands</skipped></testcase><testcase classname="test.e2e.tests.test_config_tenant.TestConfigAnchorPresence" name="test_cluster_config_default_exists" time="0.400" /><testcase classname="test.e2e.tests.test_config_tenant.TestConfigAnchorPresence" name="test_cluster_config_not_terminating" time="0.140" /><testcase classname="test.e2e.tests.test_config_tenant.TestConfigTenantOwnership" name="test_tenant_lists_config_owner_reference" time="0.105" /><testcase classname="test.e2e.tests.test_config_tenant.TestConfigTenantOwnership" name="test_maas_controller_deployment_lists_config_owner_reference" time="0.115" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenFlow" name="test_oidc_token_can_create_api_key" time="55.614"><failure message="AssertionError: OIDC API key mint failed: 401 &#10;assert 401 in (200, 201)&#10; +  where 401 = &lt;Response [401]&gt;.status_code">self = &lt;test_external_oidc.TestOIDCTokenFlow object at 0x7f339332a1c0&gt;
maas_api_base_url = 'https://maas.apps.2be519f3-a56a-4801-9821-e5615bf56ec5.prod.konfluxeaas.com/maas-api'

    def test_oidc_token_can_create_api_key(self, maas_api_base_url: str):
        """OIDC token from default user (alice_lead) can mint an API key."""
        token = _request_oidc_token()
&gt;       data = _create_oidc_api_key(maas_api_base_url, token)

test/e2e/tests/test_external_oidc.py:207: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

maas_api_base_url = 'https://maas.apps.2be519f3-a56a-4801-9821-e5615bf56ec5.prod.konfluxeaas.com/maas-api'
oidc_token = 'eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJxVDJDY1JhYl9pdDEzc3BOdGRCeDNHUUd2MFRYMjNiUzA0aG5xcDFyVnhBIn0.eyJle...oSs9UCKXQ9MLHyVxk3-rOfqC4dm7R7QHdA-ZpVk4EwaGoSB4FNXKwVkZNnoua6jwprsbka41qy0-CZ1QQV4VYbMWIDGrYu7m-M38Fxc7mVDQGEOP1X5ALQ'
name = None, subscription = None

    def _create_oidc_api_key(
        maas_api_base_url: str,
        oidc_token: str,
        name: str | None = None,
        subscription: str | None = None,
    ) -&gt; dict:
        """Mint a MaaS API key using an OIDC bearer token."""
        body: dict = {"name": name or f"e2e-oidc-{uuid.uuid4().hex[:8]}"}
        if subscription:
            body["subscription"] = subscription
    
        response = _oidc_request_with_retry(
            requests.post,
            f"{maas_api_base_url}/v1/api-keys",
            oidc_token,
            label="OIDC API key mint",
            json=body,
        )
    
&gt;       assert response.status_code in (200, 201), (
            f"OIDC API key mint failed: {response.status_code} {response.text}"
        )
E       AssertionError: OIDC API key mint failed: 401 
E       assert 401 in (200, 201)
E        +  where 401 = &lt;Response [401]&gt;.status_code

test/e2e/tests/test_external_oidc.py:174: AssertionError</failure></testcase><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenFlow" name="test_invalid_oidc_token_gets_401" time="0.112" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenFlow" name="test_empty_bearer_token_gets_401" time="0.023" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenFlow" name="test_no_auth_header_gets_401" time="0.029" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenClaims" name="test_token_contains_groups_claim" time="0.066" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenClaims" name="test_token_contains_preferred_username" time="0.069" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCTokenClaims" name="test_different_users_have_different_groups" time="0.150" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCMultiUser" name="test_bob_sre_can_mint_api_key" time="55.564"><failure message="AssertionError: OIDC API key mint failed: 401 &#10;assert 401 in (200, 201)&#10; +  where 401 = &lt;Response [401]&gt;.status_code">self = &lt;test_external_oidc.TestOIDCMultiUser object at 0x7f33935d9940&gt;
maas_api_base_url = 'https://maas.apps.2be519f3-a56a-4801-9821-e5615bf56ec5.prod.konfluxeaas.com/maas-api'

    def test_bob_sre_can_mint_api_key(self, maas_api_base_url: str):
        """bob_sre (Site-Reliability group) can also mint an API key."""
        token = _request_oidc_token(username="bob_sre", password="letmein")
&gt;       data = _create_oidc_api_key(maas_api_base_url, token, name=f"e2e-bob-{uuid.uuid4().hex[:8]}")

test/e2e/tests/test_external_oidc.py:315: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

maas_api_base_url = 'https://maas.apps.2be519f3-a56a-4801-9821-e5615bf56ec5.prod.konfluxeaas.com/maas-api'
oidc_token = 'eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJxVDJDY1JhYl9pdDEzc3BOdGRCeDNHUUd2MFRYMjNiUzA0aG5xcDFyVnhBIn0.eyJle...zoWekN1tJljHMiuDlBsl2JLPbLiyaq8bHdcLEcpxqkPcbYPKM08JikfJiULQQN9H_j9t60P86XtCNMeIzZuwinQt0bKGIz_ArJZQGWsaPvG1VSv8tugfFA'
name = 'e2e-bob-77b0a3ad', subscription = None

    def _create_oidc_api_key(
        maas_api_base_url: str,
        oidc_token: str,
        name: str | None = None,
        subscription: str | None = None,
    ) -&gt; dict:
        """Mint a MaaS API key using an OIDC bearer token."""
        body: dict = {"name": name or f"e2e-oidc-{uuid.uuid4().hex[:8]}"}
        if subscription:
            body["subscription"] = subscription
    
        response = _oidc_request_with_retry(
            requests.post,
            f"{maas_api_base_url}/v1/api-keys",
            oidc_token,
            label="OIDC API key mint",
            json=body,
        )
    
&gt;       assert response.status_code in (200, 201), (
            f"OIDC API key mint failed: {response.status_code} {response.text}"
        )
E       AssertionError: OIDC API key mint failed: 401 
E       assert 401 in (200, 201)
E        +  where 401 = &lt;Response [401]&gt;.status_code

test/e2e/tests/test_external_oidc.py:174: AssertionError</failure></testcase><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCMultiUser" name="test_wrong_password_gets_rejected" time="0.062" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCMultiUser" name="test_nonexistent_user_gets_rejected" time="0.068" /><testcase classname="test.e2e.tests.test_external_oidc.TestOIDCModelAccess" name="test_minted_api_key_can_list_models_and_infer" time="55.579"><failure message="AssertionError: OIDC API key mint failed: 401 &#10;assert 401 in (200, 201)&#10; +  where 401 = &lt;Response [401]&gt;.status_code">self = &lt;test_external_oidc.TestOIDCModelAccess object at 0x7f33935d9d90&gt;
maas_api_base_url = 'https://maas.apps.2be519f3-a56a-4801-9821-e5615bf56ec5.prod.konfluxeaas.com/maas-api'

    def test_minted_api_key_can_list_models_and_infer(self, maas_api_base_url: str):
        """Complete happy path: OIDC token → API key → model list → inference."""
        token = _request_oidc_token()
&gt;       api_key = _create_oidc_api_key(maas_api_base_url, token)["key"]

test/e2e/tests/test_external_oidc.py:341: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

maas_api_base_url = 'https://maas.apps.2be519f3-a56a-4801-9821-e5615bf56ec5.prod.konfluxeaas.com/maas-api'
oidc_token = 'eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJxVDJDY1JhYl9pdDEzc3BOdGRCeDNHUUd2MFRYMjNiUzA0aG5xcDFyVnhBIn0.eyJle...fVoOoY_p-5dyG1JEn-WjEh45uOeJ4QF3yqi1T7VkLOUua1F3JaKbYB2Ae3jAnn_BxO_6aq3pGzn-iiisad6tiXO3K-8ZqPve_3OuEvFrmGjM22N4ZwhQ8A'
name = None, subscription = None

    def _create_oidc_api_key(
        maas_api_base_url: str,
        oidc_token: str,
        name: str | None = None,
        subscription: str | None = None,
    ) -&gt; dict:
        """Mint a MaaS API key using an OIDC bearer token."""
        body: dict = {"name": name or f"e2e-oidc-{uuid.uuid4().hex[:8]}"}
        if subscription:
            body["subscription"] = subscription
    
        response = _oidc_request_with_retry(
            requests.post,
            f"{maas_api_base_url}/v1/api-keys",
            oidc_token,
            label="OIDC API key mint",
            json=body,
        )
    
&gt;       assert response.status_code in (200, 201), (
            f"OIDC API key mint failed: {response.status_code} {response.text}"
        )
E       AssertionError: OIDC API key mint failed: 401 
E       assert 401 in (200, 201)
E        +  where 401 = &lt;Response [401]&gt;.status_code

test/e2e/tests/test_external_oidc.py:174: AssertionError</failure></testcase></testsuite></testsuites>