<?xml version="1.0" encoding="utf-8"?><testsuites name="pytest tests"><testsuite name="pytest" errors="0" failures="4" skipped="44" tests="255" time="998.570" timestamp="2026-09-10T21:09:58.521104+00:00" hostname="maas-group-test-vqd79-e2e-maas-openshift-pod"><testcase classname="tests.test_model_identity_conflict.TestModelIdentityConflictDetection" name="test_colliding_model_names_flagged_then_resolved@models" time="149.609" /><testcase classname="tests.test_smoke" name="test_healthz_or_404@readonly" time="0.036" /><testcase classname="tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_subscription_namespace_visible_to_api@security" time="0.004"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:214: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_another_namespace_not_visible_to_api@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:247: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_maas_subscription_namespace@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:287: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_another_namespace@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:324: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestModelRef" name="test_auth_policy_model_ref@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:382: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_namespace_scoping.TestModelRef" name="test_subscription_model_ref@security" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:456: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="tests.test_negative_security.TestAPIKeyManagementIsolation" name="test_api_key_cannot_mint_another_api_key@security" time="0.235" /><testcase classname="tests.test_smoke" name="test_tokens_endpoint_replaced_by_api_keys@readonly" time="0.035" /><testcase classname="tests.test_smoke" name="test_models_catalog@readonly" time="0.041" /><testcase classname="tests.test_smoke" name="test_chat_completions_gateway_alive@readonly" time="0.080" /><testcase classname="tests.test_api_keys.TestAPIKeyCRUD" name="test_create_api_key@api_keys" time="0.248" /><testcase classname="tests.test_smoke" name="test_legacy_completions_optionally@readonly" time="0.040" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_forged_identity_headers_rejected_on_key_mint[username-only]@security" time="0.295" /><testcase classname="tests.test_api_keys.TestAPIKeyCRUD" name="test_list_api_keys@api_keys" time="0.145" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_default_aitenant_bootstraps_maas_tenant_config_without_gateway_mutation@mt_lifecycle" time="1.586" /><testcase classname="tests.test_api_keys.TestAPIKeyCRUD" name="test_revoke_api_key@api_keys" time="0.099" /><testcase classname="tests.test_tenant.TestTenantLifecycle" name="test_tenant_ready_and_phase_healthy@readonly" time="0.336" /><testcase classname="tests.test_api_keys.TestAPIKeyAuthorization" name="test_admin_manage_other_users_keys@api_keys" time="0.156" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_forged_identity_headers_rejected_on_key_mint[group-only]@security" time="0.321" /><testcase classname="tests.test_tenant.TestTenantContract" name="test_status_has_phase_and_conditions@readonly" time="0.125" /><testcase classname="tests.test_api_keys.TestAPIKeyAuthorization" name="test_non_admin_cannot_access_other_users_keys@api_keys" time="0.124" /><testcase classname="tests.test_tenant.TestTenantContract" name="test_spec_is_well_formed@readonly" time="0.099" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_own_keys@api_keys" time="0.289" /><testcase classname="tests.test_tenant.TestTenantContract" name="test_conditions_use_kubernetes_metav1_shape@readonly" time="0.111" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_injected_identity_headers_rejected_on_inference@security" time="0.179" /><testcase classname="tests.test_tenant.TestTenantNoFalseOwnership" name="test_maas_user_crs_not_owned_by_tenant@readonly" time="0.345" /><testcase classname="tests.test_negative_security.TestHeaderSpoofing" name="test_duplicate_subscription_headers_ignored@security" time="30.787"><failure message="AssertionError: Expected 200 (API key subscription binding wins over duplicate headers), got 403: &#10;assert 403 == 200">self = &lt;test_negative_security.TestHeaderSpoofing object at 0x7fcad9ddf2e0&gt;

    def test_duplicate_subscription_headers_ignored(self):
        """Client sends multiple X-MaaS-Subscription headers — API key binding wins.
    
        For API key requests, the subscription is fixed at mint time.
        Duplicate or conflicting X-MaaS-Subscription headers must not override
        the key-derived subscription.
        """
        _wait_for_gateway_auth_enforced()
        api_key = _create_api_key(_get_cluster_token(), subscription=SIMULATOR_SUBSCRIPTION)
    
        # Warm up: confirm the API key works with a normal request before
        # testing duplicate headers. Under parallel load, Rego policy
        # propagation can take longer than the 30s retry window below.
        _poll_status(api_key, 200, timeout=60)
    
        # Use http.client to send genuinely duplicate X-MaaS-Subscription headers.
        # The requests library uses a dict for headers, so it cannot send two
        # headers with the same name — the second value overwrites the first.
        path = f"{MODEL_PATH}/v1/completions"
        body = json.dumps({"model": MODEL_NAME, "prompt": "Hello", "max_tokens": 3})
    
        # Two separate X-MaaS-Subscription header lines
        headers = [
            ("Authorization", f"Bearer {api_key}"),
            ("Content-Type", "application/json"),
            ("X-MaaS-Subscription", SIMULATOR_SUBSCRIPTION),
            ("X-MaaS-Subscription", "nonexistent-fake-sub"),
        ]
    
        # As above, keep the raw duplicate headers on every retry while waiting
        # for shared gateway authorization state to settle.
        deadline = time.time() + 30
        while True:
            gateway = _gateway_url()
            parsed = urlparse(gateway)
            if parsed.scheme == "https":
                ctx = ssl.create_default_context()
                if not TLS_VERIFY:
                    ctx.check_hostname = False
                    ctx.verify_mode = ssl.CERT_NONE
                conn = http.client.HTTPSConnection(
                    parsed.hostname, parsed.port or 443, timeout=TIMEOUT, context=ctx,
                )
            else:
                conn = http.client.HTTPConnection(
                    parsed.hostname, parsed.port or 80, timeout=TIMEOUT,
                )
    
            try:
                conn.putrequest("POST", path)
                for key, value in headers:
                    conn.putheader(key, value)
                conn.putheader("Content-Length", str(len(body)))
                conn.endheaders(body.encode())
    
                resp = conn.getresponse()
                status = resp.status
                resp_body = resp.read().decode(errors="replace")
            finally:
                conn.close()
    
            if status == 200 or time.time() &gt;= deadline:
                break
            time.sleep(2)
    
        # API key binding wins — request succeeds with key-derived subscription.
        log.info("Duplicate X-MaaS-Subscription headers -&gt; %s", status)
&gt;       assert status == 200, (
            f"Expected 200 (API key subscription binding wins over duplicate headers), "
            f"got {status}: {resp_body[:500]}"
        )
E       AssertionError: Expected 200 (API key subscription binding wins over duplicate headers), got 403: 
E       assert 403 == 200

test/e2e/tests/test_negative_security.py:335: AssertionError</failure></testcase><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_other_user_forbidden@api_keys" time="0.066" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_admin_can_revoke_any_user@api_keys" time="0.119" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_by_subscription@api_keys" time="1.633" /><testcase classname="tests.test_config_tenant.TestConfigAnchorPresence" name="test_cluster_config_default_exists@readonly" time="0.381" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_rejected_outside_ai_tenants_namespace@mt_lifecycle" time="6.971" /><testcase classname="tests.test_config_tenant.TestConfigAnchorPresence" name="test_cluster_config_not_terminating@readonly" time="0.133" /><testcase classname="tests.test_config_tenant.TestConfigTenantOwnership" name="test_default_aitenant_lists_config_owner_reference@readonly" time="0.114" /><testcase classname="tests.test_config_tenant.TestConfigTenantOwnership" name="test_tenant_config_lists_config_owner_reference@readonly" time="0.106" /><testcase classname="tests.test_config_tenant.TestConfigTenantOwnership" name="test_maas_controller_deployment_does_not_list_config_owner_reference@readonly" time="0.123" /><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_requires_auth@readonly" time="5.213" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_by_subscription_forbidden_for_non_admin@api_keys" time="0.038" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_dry_run@api_keys" time="0.213" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_dry_run_by_subscription@api_keys" time="1.441" /><testcase classname="tests.test_external_models.TestExternalModelDiscovery" name="test_maasmodelref_created@external" time="3.858" /><testcase classname="tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_httproute@external" time="0.105" /><testcase classname="tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_backend_service@external" time="0.103" /><testcase classname="tests.test_external_models.TestExternalModelAuth" name="test_invalid_key_returns_401@external" time="0.053" /><testcase classname="tests.test_external_models.TestExternalModelAuth" name="test_no_key_returns_401@external" time="0.025" /><testcase classname="tests.test_external_models.TestExternalModelEgress" name="test_request_forwarded_returns_200@external" time="0.083" /><testcase classname="tests.test_external_models.TestExternalModelCleanup" name="test_delete_removes_httproute@external" time="12.618" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_combined_user_and_subscription@api_keys" time="1.776" /><testcase classname="tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_missing_scope_returns_400@api_keys" time="0.035" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_within_expiration_limit@api_keys" time="0.034" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_at_expiration_limit@api_keys" time="0.033" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_exceeds_expiration_limit@api_keys" time="0.033" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_without_expiration@api_keys" time="0.033" /><testcase classname="tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_with_short_expiration@api_keys" time="0.030" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_api_key_model_access_success@api_keys" time="0.106" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_invalid_api_key_rejected@api_keys" time="0.029" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_no_auth_header_rejected@api_keys" time="0.024" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_revoked_api_key_rejected@api_keys" time="2.298" /><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_with_invalid_token@readonly" time="2.037" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_create_bootstrap_resources@mt_lifecycle" time="45.543" /><testcase classname="tests.test_api_keys.TestAPIKeyModelInference" name="test_api_key_chat_completions@api_keys" time="0.049" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_double_revoke_returns_404@api_keys" time="0.100" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_nonexistent_key_returns_404@api_keys" time="0.031" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_then_create_new_key_works@api_keys" time="0.188" /><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_authenticated@readonly" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery.py:79: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_gateway_matches_deployment@readonly" time="0.000"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery.py:155: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery" name="test_tenant_discovery_not_exposed_through_gateway@readonly" time="0.031" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_individual_revoke_multiple_keys@api_keys" time="0.223" /><testcase classname="tests.test_tenant_auto_resolve.TestTenantAutoResolve" name="test_auto_resolve_populates_resolved_tenant_ref@tenant_auto_resolve" time="159.579" /><testcase classname="tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_keys_rejected_at_gateway@api_keys" time="0.350" /><testcase classname="tests.test_api_keys.TestEphemeralKeyCleanup" name="test_cronjob_exists_and_configured@api_keys" time="0.118" /><testcase classname="tests.test_api_keys.TestEphemeralKeyCleanup" name="test_cleanup_networkpolicy_exists@api_keys" time="0.116" /><testcase classname="tests.test_api_keys.TestEphemeralKeyCleanup" name="test_create_ephemeral_key@api_keys" time="0.120" /><testcase classname="tests.test_api_keys.TestEphemeralKeyCleanup" name="test_trigger_cleanup_preserves_active_keys@api_keys" time="0.429" /><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_active_subscription@api_keys" time="1.440" /><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_degraded_subscription@api_keys" time="3.640" /><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_failed_subscription@api_keys" time="3.540" /><testcase classname="tests.test_external_models.TestExternalModelPathRouting" name="test_wrong_path_returns_not_found@external" time="0.078" /><testcase classname="tests.test_external_models.TestLegacyExternalModelMigration" name="test_migration_sets_legacy_status_and_removes_networking@external" time="3.559" /><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionFilter" name="test_search_filters_by_subscription@api_keys" time="2.244" /><testcase classname="tests.test_external_models.TestExternalModelBodyRouting" name="test_correct_model_in_body_succeeds@external" time="0.120" /><testcase classname="tests.test_external_models.TestExternalModelBodyRouting" name="test_wrong_model_in_body_does_not_error@external" time="0.090" /><testcase classname="tests.test_external_models.TestExternalModelBodyRouting" name="test_missing_model_in_body_does_not_error@external" time="1.131" /><testcase classname="tests.test_api_keys.TestAPIKeySubscriptionFilter" name="test_search_without_subscription_returns_all@api_keys" time="0.311" /><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_oidc_token_can_create_api_key@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:252: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_invalid_oidc_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:263: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_empty_bearer_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:277: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_no_auth_header_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:290: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_tampered_expired_oidc_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:303: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenFlow" name="test_real_expired_oidc_token_gets_401@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:335: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenClaims" name="test_token_contains_groups_claim@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:379: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenClaims" name="test_token_contains_preferred_username@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:395: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCTokenClaims" name="test_different_users_have_different_groups@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:405: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiUser" name="test_bob_sre_can_mint_api_key@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:428: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiUser" name="test_wrong_password_gets_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:436: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiUser" name="test_nonexistent_user_gets_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:441: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCModelAccess" name="test_minted_api_key_can_list_models_and_infer@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:454: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCModelAccess" name="test_revoked_api_key_cannot_access_models@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:501: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCModelAccess" name="test_oidc_user_without_group_access_gets_empty_list@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:537: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiTenant" name="test_tenant_b_token_rejected_by_maas@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:602: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCMultiTenant" name="test_tenant_a_users_are_isolated@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:633: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCAPIKeyLifecycle" name="test_create_and_revoke_api_key@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:659: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCAPIKeyLifecycle" name="test_api_key_owner_matches_oidc_username@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:690: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_username_header_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:750: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_group_header_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:786: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_subscription_header_ignored@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:824: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCHeaderInjection" name="test_injected_username_on_oidc_token_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC is not true">/workspace/source/test/e2e/tests/test_external_oidc.py:872: EXTERNAL_OIDC is not true</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCClientBinding" name="test_wrong_oauth_client_token_is_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:961: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCGroupSafety" name="test_unsafe_group_name_is_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1013: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCGroupSafety" name="test_mixed_safe_and_unsafe_groups_is_rejected@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1049: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCDirectModelAccess" name="test_oidc_token_can_list_models_directly@external" time="0.000"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1103: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_external_oidc.TestOIDCAlertingInfra" name="test_authorino_prometheusrule_exists@external" time="0.001"><skipped type="pytest.skip" message="EXTERNAL_OIDC not enabled">/workspace/source/test/e2e/tests/test_external_oidc.py:1142: EXTERNAL_OIDC not enabled</skipped></testcase><testcase classname="tests.test_api_keys.TestAPIKeyLabels" name="test_create_api_key_with_labels@api_keys" time="0.069" /><testcase classname="tests.test_api_keys.TestAPIKeyLabels" name="test_search_api_keys_by_labels@api_keys" time="0.174" /><testcase classname="tests.test_api_keys.TestAPIKeyLabels" name="test_labels_validation_errors@api_keys" time="0.099" /><testcase classname="tests.test_api_keys.TestAPIKeyLabels" name="test_backward_compatibility_no_labels@api_keys" time="0.062" /><testcase classname="tests.test_subscription.TestAuthEnforcement" name="test_authorized_user_gets_200@api_keys" time="0.075" /><testcase classname="tests.test_subscription.TestAuthEnforcement" name="test_no_auth_gets_401@api_keys" time="0.027" /><testcase classname="tests.test_subscription.TestAuthEnforcement" name="test_invalid_token_gets_403@api_keys" time="0.045" /><testcase classname="tests.test_subscription.TestAuthEnforcement" name="test_wrong_group_gets_403@api_keys" time="0.031" /><testcase classname="tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_uses_highest_priority_subscription@api_keys" time="0.301" /><testcase classname="tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_with_explicit_simulator_subscription@api_keys" time="0.072" /><testcase classname="tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_nonexistent_subscription_errors@api_keys" time="0.252" /><testcase classname="tests.test_subscription.TestSubscriptionEnforcement" name="test_subscribed_user_gets_200@api_keys" time="0.151" /><testcase classname="tests.test_subscription.TestSubscriptionEnforcement" name="test_auth_pass_no_subscription_gets_403@api_keys" time="0.609" /><testcase classname="tests.test_subscription.TestMultipleAuthPoliciesPerModel" name="test_two_auth_policies_or_logic@api_keys" time="1.134" /><testcase classname="tests.test_subscription.TestCascadeDeletion" name="test_unconfigured_model_denied_by_gateway_auth@api_keys" time="0.633" /><testcase classname="tests.test_subscription.TestOrderingEdgeCases" name="test_subscription_before_auth_policy@api_keys" time="12.511" /><testcase classname="tests.test_negative_security.TestExpiredKeyRejection" name="test_expired_key_rejected_at_gateway@security" time="5.076" /><testcase classname="tests.test_negative_security.TestCrossModelAccess" name="test_key_cannot_access_model_outside_subscription@security" time="0.201" /><testcase classname="tests.test_negative_security.TestMissingModelRef" name="test_subscription_with_nonexistent_model_ref@security" time="1.028" /><testcase classname="tests.test_negative_security.TestMissingModelRef" name="test_authpolicy_with_nonexistent_model_ref@security" time="0.651" /><testcase classname="tests.test_subscription.TestManagedAnnotation" name="test_authpolicy_managed_false_prevents_update@api_keys" time="0.215"><skipped type="pytest.skip" message="gateway-only mode: per-model AuthPolicy is not created">/workspace/source/test/e2e/tests/test_subscription.py:1069: gateway-only mode: per-model AuthPolicy is not created</skipped></testcase><testcase classname="tests.test_subscription.TestManagedAnnotation" name="test_trlp_managed_false_prevents_update@api_keys" time="5.353" /><testcase classname="tests.test_negative_security.TestHeaderAbuse" name="test_special_characters_in_subscription_header@security" time="0.339" /><testcase classname="tests.test_negative_security.TestWebhookValidation" name="test_subscription_rejected_in_unlabeled_namespace@security" time="6.494" /><testcase classname="tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_both_access_and_subscription_gets_200@api_keys" time="1.788" /><testcase classname="tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_subscription_but_no_access_gets_403@api_keys" time="1.792" /><testcase classname="tests.test_negative_security.TestWebhookValidation" name="test_authpolicy_rejected_in_unlabeled_namespace@security" time="7.320" /><testcase classname="tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_multiple_subscriptions_separate_keys_gets_200@api_keys" time="1.878" /><testcase classname="tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_mint_api_key_denied_for_inaccessible_subscription@api_keys" time="2.065" /><testcase classname="tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_access_gets_200@api_keys" time="1.768" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_internal_endpoint_not_routable[subscriptions-select]@security" time="0.136" /><testcase classname="tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_subscription_but_no_auth_gets_403@api_keys" time="3.689" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_internal_endpoint_not_routable[api-keys-cleanup]@security" time="0.143" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_internal_endpoint_not_routable[api-keys-validate]@security" time="0.138" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_health_endpoint_accessible@security" time="0.029" /><testcase classname="tests.test_negative_security.TestInternalEndpointIsolation" name="test_v1_models_via_maas_api_prefix@security" time="0.158" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_migrates_and_removes_legacy_tenant@mt_lifecycle" time="36.198" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_subscription_active_status_with_valid_model@api_keys" time="1.449" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_subscription_failed_status_with_missing_model@api_keys" time="0.927" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_authpolicy_active_status_with_valid_model@api_keys" time="3.097" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_authpolicy_failed_status_with_missing_model@api_keys" time="0.876" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_subscription_degraded_status_with_partial_models@api_keys" time="1.242" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_authpolicy_degraded_status_with_partial_models@api_keys" time="0.871" /><testcase classname="tests.test_subscription.TestStatusReporting" name="test_subscription_status_transitions_on_model_deletion@api_keys" time="8.630" /><testcase classname="tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_degraded_healthy_model_allows_inference@api_keys" time="1.297" /><testcase classname="tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_failed_subscription_blocks_inference@api_keys" time="1.558" /><testcase classname="tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_models_endpoint_with_degraded_subscription_api_key@api_keys" time="1.251" /><testcase classname="tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_models_endpoint_with_degraded_subscription_kube_token@api_keys" time="1.218" /><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptions" name="test_returns_accessible_subscriptions@api_keys" time="0.364" /><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptions" name="test_unauthenticated_returns_401@api_keys" time="0.026" /><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptions" name="test_subscription_includes_model_refs@api_keys" time="0.878" /><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptions" name="test_model_ref_display_name_and_description_enriched@api_keys" time="10.126"><failure message="AssertionError: Expected 200, got 500: {&quot;error&quot;:&quot;Exception thrown while generating token&quot;,&quot;exceptionCode&quot;:&quot;AUTH_FAILURE&quot;,&quot;refId&quot;:&quot;001&quot;}&#10;assert 500 == 200&#10; +  where 500 = &lt;Response [500]&gt;.status_code">self = &lt;test_subscription_list_endpoints.TestListSubscriptions object at 0x7fd02496a3a0&gt;

    def test_model_ref_display_name_and_description_enriched(self):
        """Model refs include display_name and description from MaaSModelRef annotations."""
        sa_name = "e2e-enrichment-sa"
        sa_ns = "default"
        maas_ns = _ns()
        model_ref_name = "e2e-enrichment-model-ref"
        model_ns = MODEL_NAMESPACE
        subscription_name = "e2e-enrichment-sub"
        auth_policy_name = "e2e-enrichment-auth"
        expected_display_name = "E2E Enrichment Test Model"
        expected_description = "Model created by e2e test to verify display_name/description enrichment"
    
        try:
            sa_token = _create_sa_token(sa_name, namespace=sa_ns)
            sa_user = _sa_to_user(sa_name, namespace=sa_ns)
    
            # Create a MaaSModelRef with display-name and description annotations.
            # Points to the existing e2e-distinct-simulated LLMIS so the controller
            # can reconcile the subscription to Active.
            _apply_cr({
                "apiVersion": "maas.opendatahub.io/v1alpha1",
                "kind": "MaaSModelRef",
                "metadata": {
                    "name": model_ref_name,
                    "namespace": model_ns,
                    "annotations": {
                        "openshift.io/display-name": expected_display_name,
                        "openshift.io/description": expected_description,
                    },
                },
                "spec": {
                    "modelRef": {
                        "kind": "LLMInferenceService",
                        "name": "e2e-distinct-simulated",
                    }
                },
            })
    
            _create_test_subscription(
                subscription_name,
                model_ref_name,
                users=[sa_user],
            )
    
            _create_test_auth_policy(
                auth_policy_name,
                model_ref_name,
                users=[sa_user],
            )
    
            api_key = _create_api_key(sa_token, name=f"{sa_name}-key")
    
            _wait_for_maas_subscription_phase(subscription_name, namespace=maas_ns)
            _wait_for_maas_auth_policy_phase(auth_policy_name, require_enforced=False, namespace=maas_ns)
    
            url = f"{_maas_api_url()}/v1/subscriptions"
            r = requests.get(
                url,
                headers={"Authorization": f"Bearer {api_key}"},
                timeout=TIMEOUT,
                verify=TLS_VERIFY,
            )
    
&gt;           assert r.status_code == 200, f"Expected 200, got {r.status_code}: {r.text}"
E           AssertionError: Expected 200, got 500: {"error":"Exception thrown while generating token","exceptionCode":"AUTH_FAILURE","refId":"001"}
E           assert 500 == 200
E            +  where 500 = &lt;Response [500]&gt;.status_code

test/e2e/tests/test_subscription_list_endpoints.py:264: AssertionError</failure></testcase><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_delete_cleans_maas_resources_and_preserves_user_objects@mt_lifecycle" time="37.131" /><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptionsForModel" name="test_returns_subscriptions_for_model@api_keys" time="6.481" /><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptionsForModel" name="test_unknown_model_returns_empty@api_keys" time="0.384" /><testcase classname="tests.test_subscription_list_endpoints.TestListSubscriptionsForModel" name="test_unauthenticated_returns_401@api_keys" time="0.026" /><testcase classname="tests.test_subscription_list_endpoints.TestSubscriptionModelAccessFiltering" name="test_filters_unauthorized_models@api_keys" time="7.682" /><testcase classname="tests.test_subscription_list_endpoints.TestSubscriptionModelAccessFiltering" name="test_omits_subscription_with_no_authorized_models@api_keys" time="5.882" /><testcase classname="tests.test_embedding_inference.TestEmbeddingPathRouting" name="test_embedding_path_based_200@api_keys" time="0.047" /><testcase classname="tests.test_embedding_inference.TestEmbeddingPathRouting" name="test_embedding_bbr_llmisvc_200@api_keys" time="13.682" /><testcase classname="tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_derives_non_default_tenant_namespace@mt_lifecycle" time="36.158" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_explicit_subscription_header@models" time="1.238" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_empty_subscription_header_value@models" time="0.395" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_models_filtered_by_subscription@models" time="0.859" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_deduplication_same_model_multiple_refs@models" time="1.481" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_multiple_distinct_models_in_subscription@models" time="12.570" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_labeled_tenant_namespace_is_discovered@mt_lifecycle" time="8.512" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_user_token_returns_all_models@models" time="9.076" /><testcase classname="tests.test_tenant_auto_resolve.TestTenantAutoResolve" name="test_explicit_tenant_ref_preserved@tenant_auto_resolve" time="60.255" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_label_removal_stops_reconciliation@mt_lifecycle" time="32.687" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_user_token_with_subscription_header_filters@models" time="1.481" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_response_schema_matches_openapi@models" time="0.365" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_model_metadata_preserved@models" time="0.371" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_scoped_to_subscription@models" time="1.437" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_with_deleted_subscription_403@models" time="1.479"><failure message="AssertionError: Expected 403 for API key with deleted subscription, got 200: {&quot;data&quot;:[],&quot;object&quot;:&quot;list&quot;}&#10;assert 200 == 403&#10; +  where 200 = &lt;Response [200]&gt;.status_code">self = &lt;test_models_endpoint.TestModelsEndpoint object at 0x7f7afd5edbb0&gt;

    def test_api_key_with_deleted_subscription_403(self):
        """
        Test: API key bound to a subscription that was deleted after key creation.
    
        This tests an edge case where an API key was minted with a subscription,
        but that subscription is later deleted. The gateway injects X-MaaS-Subscription
        from the key, but the subscription no longer exists.
    
        Expected: HTTP 403 with error type: permission_error
        """
        ns = _ns()
        auth_policy_name = "e2e-api-key-deleted-sub-auth"
        subscription_name = "e2e-api-key-deleted-sub"
        sa_name = "e2e-api-key-deleted-sub-sa"
        api_key = None
    
        try:
            # Create service account and token
            oc_token = _create_sa_token(sa_name, namespace=ns)
            sa_user = _sa_to_user(sa_name, namespace=ns)
    
            # Create test resources
            _create_test_auth_policy(auth_policy_name, MODEL_REF, users=[sa_user])
            _create_test_subscription(subscription_name, MODEL_REF, users=[sa_user])
    
            # Wait for subscription to reconcile before creating API key
            _wait_for_maas_subscription_phase(subscription_name, namespace=ns)
    
            # Create API key bound to subscription
            api_key = _create_api_key(oc_token, name=f"{sa_name}-key", subscription=subscription_name)
    
            _wait_for_maas_auth_policy_phase(auth_policy_name, require_enforced=False)
    
            # Delete the subscription (simulating deletion after key creation)
            log.info(f"Deleting subscription {subscription_name} after API key creation")
            _delete_cr("maassubscription", subscription_name, namespace=ns)
            _wait_for_cr_absent("maassubscription", subscription_name, namespace=ns)
    
            # Query with API key (gateway injects deleted subscription name)
            log.info("Querying /v1/models with API key bound to deleted subscription")
            r = _request_with_gateway_retry(
                requests.get,
                f"{_maas_api_url()}/v1/models",
                headers={
                    "Authorization": f"Bearer {api_key}",
                },
            )
    
            # Should return 403 because subscription doesn't exist
&gt;           assert r.status_code == 403, \
                f"Expected 403 for API key with deleted subscription, got {r.status_code}: {r.text}"
E               AssertionError: Expected 403 for API key with deleted subscription, got 200: {"data":[],"object":"list"}
E               assert 200 == 403
E                +  where 200 = &lt;Response [200]&gt;.status_code

test/e2e/tests/test_models_endpoint.py:1586: AssertionError</failure></testcase><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_with_inaccessible_subscription_403@models" time="1.733" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_invalid_subscription_header_403@models" time="1.424" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_access_denied_to_subscription_403@models" time="2.134" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_ignores_subscription_header@models" time="22.793" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_unlabeled_namespace_ignored@mt_lifecycle" time="22.837" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_multiple_api_keys_different_subscriptions@models" time="8.737" /><testcase classname="tests.test_tenant_model_inference.TestTenantModelInference" name="test_model_routes_through_tenant_gateway@tenant_isolation" time="212.483" /><testcase classname="tests.test_tenant_model_inference.TestTenantModelInference" name="test_inference_succeeds_through_tenant_gateway@tenant_isolation" time="8.268" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_service_account_token_multiple_subs_no_header@models" time="8.909" /><testcase classname="tests.test_tenant_model_inference.TestTenantModelInference" name="test_tenant_isolation_cross_gateway_blocked@tenant_isolation" time="0.315" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_correct_model_in_body_succeeds@tenant_isolation" time="8.195" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_service_account_token_multiple_subs_with_header@models" time="6.826" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_dynamic_discovery_after_label_added@mt_lifecycle" time="17.654" /><testcase classname="tests.test_tenant_auto_resolve.TestTenantAutoResolve" name="test_no_matching_tenant_enters_failed@tenant_auto_resolve" time="56.523" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_wrong_model_in_body_rejected@tenant_isolation" time="8.192" /><testcase classname="tests.test_models_endpoint.TestModelsEndpoint" name="test_unauthenticated_request_401@models" time="0.032" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyStructure" name="test_target_ref_points_to_gateway@models" time="0.211" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyStructure" name="test_no_per_model_authpolicy_for_fixture_model@models" time="0.103" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyLifecycle" name="test_gateway_auth_rego_is_fixed_size@models" time="1.078" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyLifecycle" name="test_only_one_gateway_authpolicy_named_maas_gateway_auth@models" time="0.224" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyManagementEndpointAccess" name="test_gateway_auth_group_membership_has_when_guard@models" time="0.104" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyManagementEndpointAccess" name="test_gateway_auth_subscription_check_gated_by_model_identity@models" time="0.108" /><testcase classname="tests.test_gateway_scoped_authpolicy.TestGatewayAuthPolicyManagementEndpointAccess" name="test_gateway_default_auth_scoped_if_present@models" time="0.107"><skipped type="pytest.skip" message="gateway-default-auth not present (maas-gateway-auth is active); scoping is validated by unit tests">/workspace/source/test/e2e/tests/test_gateway_scoped_authpolicy.py:212: gateway-default-auth not present (maas-gateway-auth is active); scoping is validated by unit tests</skipped></testcase><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_missing_model_in_body_rejected@tenant_isolation" time="8.201" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_per_tenant_oidc_configuration@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="OIDC_ISSUER_URL not set; per-tenant OIDC E2E requires external OIDC deploy">/workspace/source/test/e2e/tests/test_tenant_namespace_discovery.py:189: OIDC_ISSUER_URL not set; per-tenant OIDC E2E requires external OIDC deploy</skipped></testcase><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_namespace_qualified_collision_prevention@mt_lifecycle" time="15.333" /><testcase classname="tests.test_tenant_model_inference.TestTenantBodyRouting" name="test_each_tenant_routes_to_own_model@tenant_isolation" time="56.885" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantNamespaceDiscovery" name="test_tenant_admin_rbac_is_namespace_scoped@mt_lifecycle" time="54.837" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantWebhookValidation" name="test_maassubscription_rejected_without_tenant_config_cr@mt_lifecycle" time="6.288" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantWebhookValidation" name="test_maasauthpolicy_rejected_without_tenant_config_cr@mt_lifecycle" time="6.574" /><testcase classname="tests.test_tenant_namespace_discovery.TestTenantDiscoveryDormantMode" name="test_dormant_mode_ignores_labeled_namespace@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="Dormant-mode test mutates controller flags; set ENABLE_TENANT_DISCOVERY_DORMANT_E2E=true">/workspace/source/test/e2e/tests/test_tenant_namespace_discovery.py:355: Dormant-mode test mutates controller flags; set ENABLE_TENANT_DISCOVERY_DORMANT_E2E=true</skipped></testcase><testcase classname="tests.test_tenant_namespace_discovery.TestLegacyDefaultNamespaceStillWorks" name="test_models_as_a_service_namespace_reconciles@mt_lifecycle" time="0.552" /><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_same_tenant_access@mt_lifecycle" time="57.444"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery_isolation.py:93: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_cross_tenant_isolation@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery_isolation.py:141: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_unauthorized_access@mt_lifecycle" time="8.403" /><testcase classname="tests.test_tenant_discovery_isolation" name="test_tenant_discovery_each_tenant_returns_own_gateway@mt_lifecycle" time="0.001"><skipped type="pytest.skip" message="Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.">/workspace/source/test/e2e/tests/test_tenant_discovery_isolation.py:228: Skipping when Gateway uses ClusterIP + OpenShift Route (unsupported configuration). This mixes incompatible routing paradigms. Gateway has no external hostname in spec.listeners, so /v1/tenants returns an error. Supported configuration: LoadBalancer service with hostname in spec.listeners.</skipped></testcase><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_full_tenant_lifecycle_create_to_delete@mt_lifecycle" time="133.288" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_creation_scoped_to_tenant@tenant_isolation" time="132.078" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_validates_against_correct_tenant@tenant_isolation" time="17.297" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_rejected_cross_tenant@tenant_isolation" time="19.386" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_oidc_token_validation_per_tenant@tenant_isolation" time="0.001"><skipped type="pytest.skip" message="Per-tenant OIDC tokens unavailable — set OIDC_TOKEN_URL (tenant-a) and OIDC_TOKEN_URL_TENANT_B (tenant-b), or OIDC_TOKEN_TENANT_A / OIDC_TOKEN_TENANT_B">/workspace/source/test/e2e/tests/test_tenant_auth_isolation.py:215: Per-tenant OIDC tokens unavailable — set OIDC_TOKEN_URL (tenant-a) and OIDC_TOKEN_URL_TENANT_B (tenant-b), or OIDC_TOKEN_TENANT_A / OIDC_TOKEN_TENANT_B</skipped></testcase><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_list_scoped_to_tenant@tenant_isolation" time="17.298" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_metadata_not_leaked_cross_tenant@tenant_isolation" time="15.253" /><testcase classname="tests.test_tenant_auth_isolation.TestTenantAuthIsolation" name="test_api_key_subscription_selection_uses_tenant_namespace@tenant_isolation" time="24.636" /><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_default_tenant_unaffected_by_multitenancy_enablement@mt_lifecycle" time="0.927" /><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_same_named_resources_across_tenants@mt_lifecycle" time="16.265" /><testcase classname="tests.test_multi_tenant_integration.TestMultiTenantIntegration" name="test_tenant_namespace_label_change_triggers_reconciliation@mt_lifecycle" time="39.768" /><testcase classname="tests.test_tenant_subscription_isolation.TestTenantSubscriptionIsolation" name="test_subscription_list_scoped_to_tenant@tenant_isolation" time="83.676" /><testcase classname="tests.test_tenant_subscription_isolation.TestTenantSubscriptionIsolation" name="test_subscription_selection_per_tenant@tenant_isolation" time="27.413" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_aitenant_creates_dedicated_maas_api_infrastructure@mt_lifecycle" time="59.724" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_tenant_name_environment_variable_set@mt_lifecycle" time="0.212" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_service_routing_isolation@mt_lifecycle" time="0.436" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_httproute_tenant_attachment@mt_lifecycle" time="0.223" /><testcase classname="tests.test_multi_tenant_maas_api.TestPerTenantMaaSAPI" name="test_default_and_multiple_tenants_coexist@mt_lifecycle" time="86.715" /><testcase classname="tests.test_tenant_rate_limit_isolation.TestTenantRateLimitIsolation" name="test_rate_limit_enforced_per_tenant@tenant_isolation" time="72.009"><failure message="AssertionError: Tenant A hit 429 before any successful inference: status=429 body=Too Many Requests&#10;  &#10;assert 0 &gt; 0">self = &lt;test_tenant_rate_limit_isolation.TestTenantRateLimitIsolation object at 0x7f4d16577e50&gt;
tenant_rate_limit_setup = {'key_a': 'sk-oai-4ar2GsQWo9D09QRf_E5fMNmWEQaoXC3GJT2dO73ZBFVCMpx3E1Bj3amWII6u', 'key_b': 'sk-oai-1Q0CiolNrenxhpaRZ_YJ...VAS3YjGwu9ladf0ImtFkjCYXi4jn63U', 'policy': 'e2e-rate-iso-auth-c609f3', 'subscription_a': 'e2e-rate-iso-a-c609f3', ...}

    def test_rate_limit_enforced_per_tenant(self, tenant_rate_limit_setup):
        """5.1: Tenant A's low quota is enforced on Tenant A traffic."""
        tenant_a = tenant_rate_limit_setup["tenant_a"]
        successes, response = _exhaust_until_429(
            tenant_a["base_url"],
            tenant_rate_limit_setup["key_a"],
            tenant_a["model_path"],
            tenant_a["backend_model_name"],
        )
&gt;       assert successes &gt; 0, f"Tenant A hit 429 before any successful inference: {response_summary(response)}"
E       AssertionError: Tenant A hit 429 before any successful inference: status=429 body=Too Many Requests
E         
E       assert 0 &gt; 0

test/e2e/tests/test_tenant_rate_limit_isolation.py:209: AssertionError</failure></testcase><testcase classname="tests.test_tenant_rate_limit_isolation.TestTenantRateLimitIsolation" name="test_independent_tenant_rate_limits@tenant_isolation" time="12.439" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_per_tenant_ipp_deployments_exist@tenant_isolation" time="59.071" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_per_tenant_ipp_env_vars@tenant_isolation" time="0.220" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_per_tenant_envoyfilter_workload_selector_isolated@tenant_isolation" time="0.352" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_per_tenant_envoyfilter_grpc_clusters@tenant_isolation" time="0.230" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_default_tenant_keeps_legacy_ipp_names@tenant_isolation" time="0.220" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_multiple_tenant_ipp_stacks_coexist@tenant_isolation" time="0.328" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPInfrastructure" name="test_per_tenant_networkpolicy_when_applied@tenant_isolation" time="0.233" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPRouting" name="test_default_gateway_hits_default_ipp_only@tenant_isolation" time="2.529" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPRouting" name="test_tenant_gateway_hits_tenant_ipp_only@tenant_isolation" time="41.112" /><testcase classname="tests.test_per_tenant_ipp_isolation.TestPerTenantIPPCleanup" name="test_ipp_resources_removed_on_aitenant_delete@tenant_isolation" time="168.275" /></testsuite></testsuites>