<?xml version="1.0" encoding="utf-8"?><testsuites name="pytest tests"><testsuite name="pytest" errors="0" failures="5" skipped="7" tests="135" time="1887.614" timestamp="2026-07-31T21:39:59.832642+00:00" hostname="maas-group-test-vwb7b-e2e-maas-openshift-pod"><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyCRUD" name="test_create_api_key" time="0.260" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyCRUD" name="test_list_api_keys" time="0.224" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyCRUD" name="test_revoke_api_key" time="0.227" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyAuthorization" name="test_admin_manage_other_users_keys" time="0.220" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyAuthorization" name="test_non_admin_cannot_access_other_users_keys" time="0.192" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_own_keys" time="0.359" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_other_user_forbidden" time="0.037" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyBulkOperations" name="test_bulk_revoke_admin_can_revoke_any_user" time="0.122" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_within_expiration_limit" time="0.034" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_at_expiration_limit" time="0.041" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_exceeds_expiration_limit" time="0.035" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_without_expiration" time="0.032" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyExpiration" name="test_create_key_with_short_expiration" time="0.052" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_api_key_model_access_success" time="0.115" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_invalid_api_key_rejected" time="0.030" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_no_auth_header_rejected" time="0.036" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_revoked_api_key_rejected" time="2.140" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyModelInference" name="test_api_key_chat_completions" time="0.035" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_double_revoke_returns_404" time="0.096" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_nonexistent_key_returns_404" time="0.030" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_then_create_new_key_works" time="0.157" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_individual_revoke_multiple_keys" time="0.186" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeyRevocationE2E" name="test_revoke_keys_rejected_at_gateway" time="0.313" /><testcase classname="test.e2e.tests.test_api_keys.TestEphemeralKeyCleanup" name="test_cronjob_exists_and_configured" time="0.108" /><testcase classname="test.e2e.tests.test_api_keys.TestEphemeralKeyCleanup" name="test_cleanup_networkpolicy_exists" time="0.101" /><testcase classname="test.e2e.tests.test_api_keys.TestEphemeralKeyCleanup" name="test_create_ephemeral_key" time="0.100" /><testcase classname="test.e2e.tests.test_api_keys.TestEphemeralKeyCleanup" name="test_trigger_cleanup_preserves_active_keys" time="0.468" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_active_subscription" time="5.251" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_degraded_subscription" time="15.149" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_failed_subscription" time="5.251" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_create_key_for_pending_subscription" time="79.800" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionPhases" name="test_reject_key_for_unreconciled_subscription" time="18.471" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionFilter" name="test_search_filters_by_subscription" time="13.986" /><testcase classname="test.e2e.tests.test_api_keys.TestAPIKeySubscriptionFilter" name="test_search_without_subscription_returns_all" time="0.312" /><testcase classname="test.e2e.tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_subscription_namespace_visible_to_api" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:212: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="test.e2e.tests.test_namespace_scoping.TestMaaSAPIWatchNamespace" name="test_subscription_in_another_namespace_not_visible_to_api" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:245: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="test.e2e.tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_maas_subscription_namespace" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:283: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="test.e2e.tests.test_namespace_scoping.TestMaaSControllerWatchNamespace" name="test_authpolicy_and_subscription_in_another_namespace" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:320: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="test.e2e.tests.test_namespace_scoping.TestModelRef" name="test_auth_policy_model_ref" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:377: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="test.e2e.tests.test_namespace_scoping.TestModelRef" name="test_subscription_model_ref" time="0.000"><skipped type="pytest.skip" message="test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true">/workspace/source/test/e2e/tests/test_namespace_scoping.py:453: test_namespace_scoping validates single-tenant dormant mode; skipped when ENABLE_TENANT_NAMESPACE_DISCOVERY=true</skipped></testcase><testcase classname="test.e2e.tests.test_negative_security.TestHeaderSpoofing" name="test_injected_identity_headers_ignored" time="0.203" /><testcase classname="test.e2e.tests.test_negative_security.TestHeaderSpoofing" name="test_duplicate_subscription_headers_ignored" time="0.210" /><testcase classname="test.e2e.tests.test_negative_security.TestExpiredKeyRejection" name="test_expired_key_rejected_at_gateway" time="5.075" /><testcase classname="test.e2e.tests.test_negative_security.TestCrossModelAccess" name="test_key_cannot_access_model_outside_subscription" time="0.209" /><testcase classname="test.e2e.tests.test_negative_security.TestAuthPolicyRemoval" name="test_authpolicy_deletion_revokes_access" time="11.460" /><testcase classname="test.e2e.tests.test_negative_security.TestMissingModelRef" name="test_subscription_with_nonexistent_model_ref" time="1.008" /><testcase classname="test.e2e.tests.test_negative_security.TestMissingModelRef" name="test_authpolicy_with_nonexistent_model_ref" time="11.190" /><testcase classname="test.e2e.tests.test_negative_security.TestHeaderAbuse" name="test_special_characters_in_subscription_header" time="0.317" /><testcase classname="test.e2e.tests.test_negative_security.TestWebhookValidation" name="test_subscription_rejected_in_unlabeled_namespace" time="6.434" /><testcase classname="test.e2e.tests.test_negative_security.TestWebhookValidation" name="test_authpolicy_rejected_in_unlabeled_namespace" time="6.344" /><testcase classname="test.e2e.tests.test_subscription.TestAuthEnforcement" name="test_authorized_user_gets_200" time="0.083" /><testcase classname="test.e2e.tests.test_subscription.TestAuthEnforcement" name="test_no_auth_gets_401" time="0.023" /><testcase classname="test.e2e.tests.test_subscription.TestAuthEnforcement" name="test_invalid_token_gets_403" time="0.055" /><testcase classname="test.e2e.tests.test_subscription.TestAuthEnforcement" name="test_wrong_group_gets_403" time="0.042" /><testcase classname="test.e2e.tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_uses_highest_priority_subscription" time="0.299" /><testcase classname="test.e2e.tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_with_explicit_simulator_subscription" time="0.066" /><testcase classname="test.e2e.tests.test_subscription.TestAPIKeySubscriptionBinding" name="test_create_api_key_nonexistent_subscription_errors" time="0.260" /><testcase classname="test.e2e.tests.test_subscription.TestSubscriptionEnforcement" name="test_subscribed_user_gets_200" time="0.038" /><testcase classname="test.e2e.tests.test_subscription.TestSubscriptionEnforcement" name="test_auth_pass_no_subscription_gets_403" time="8.417" /><testcase classname="test.e2e.tests.test_subscription.TestSubscriptionEnforcement" name="test_rate_limit_exhaustion_gets_429" time="16.733" /><testcase classname="test.e2e.tests.test_subscription.TestSubscriptionEnforcement" name="test_models_endpoint_exempt_from_rate_limiting" time="21.161" /><testcase classname="test.e2e.tests.test_subscription.TestMultipleSubscriptionsPerModel" name="test_user_in_one_of_two_subscriptions_gets_200" time="4.403" /><testcase classname="test.e2e.tests.test_subscription.TestMultipleAuthPoliciesPerModel" name="test_two_auth_policies_or_logic" time="10.862" /><testcase classname="test.e2e.tests.test_subscription.TestMultipleAuthPoliciesPerModel" name="test_delete_one_auth_policy_other_still_works" time="12.542" /><testcase classname="test.e2e.tests.test_subscription.TestCascadeDeletion" name="test_delete_subscription_rebuilds_trlp" time="4.520" /><testcase classname="test.e2e.tests.test_subscription.TestCascadeDeletion" name="test_trlp_persists_during_multi_subscription_deletion" time="17.307" /><testcase classname="test.e2e.tests.test_subscription.TestCascadeDeletion" name="test_delete_last_subscription_denies_access" time="7.709" /><testcase classname="test.e2e.tests.test_subscription.TestCascadeDeletion" name="test_unconfigured_model_denied_by_gateway_auth" time="0.488" /><testcase classname="test.e2e.tests.test_subscription.TestOrderingEdgeCases" name="test_subscription_before_auth_policy" time="20.232" /><testcase classname="test.e2e.tests.test_subscription.TestManagedAnnotation" name="test_authpolicy_managed_false_prevents_update" time="4.233"><skipped type="pytest.skip" message="gateway-only mode: per-model AuthPolicy is not created">/workspace/source/test/e2e/tests/test_subscription.py:1055: gateway-only mode: per-model AuthPolicy is not created</skipped></testcase><testcase classname="test.e2e.tests.test_subscription.TestManagedAnnotation" name="test_trlp_managed_false_prevents_update" time="13.202" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_both_access_and_subscription_gets_200" time="16.314" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_access_but_no_subscription_gets_403" time="9.178" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_with_subscription_but_no_access_gets_403" time="16.246" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_single_subscription_auto_selects" time="9.609" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_multiple_subscriptions_separate_keys_gets_200" time="9.513" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_mint_api_key_denied_for_inaccessible_subscription" time="9.663" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_access_gets_200" time="9.108" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_auth_but_no_subscription_gets_403" time="9.156" /><testcase classname="test.e2e.tests.test_subscription.TestE2ESubscriptionFlow" name="test_e2e_group_based_subscription_but_no_auth_gets_403" time="15.926" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_active_status_with_valid_model" time="15.876" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_failed_status_with_missing_model" time="4.744" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_authpolicy_active_status_with_valid_model" time="15.395" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_authpolicy_failed_status_with_missing_model" time="15.305" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_degraded_status_with_partial_models" time="5.085" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_degraded_trlp_blocks_inference" time="98.000" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_authpolicy_degraded_status_with_partial_models" time="15.322" /><testcase classname="test.e2e.tests.test_subscription.TestStatusReporting" name="test_subscription_status_transitions_on_model_deletion" time="70.638"><failure message="TimeoutError: MaaSAuthPolicy e2e-status-transition-auth did not reach phase 'Active' within 60s (current: phase=Pending, authPolicies=0)">self = &lt;test_subscription.TestStatusReporting object at 0x7f8f1a002b20&gt;

    def test_subscription_status_transitions_on_model_deletion(self):
        """
        Test: MaaSSubscription transitions from Active to Degraded/Failed when model is deleted.
    
        Creates a subscription with a temporary model, verifies Active status,
        then deletes the model and verifies status transitions appropriately.
        """
        ns = _ns()
        subscription_name = "e2e-status-transition-sub"
        auth_name = "e2e-status-transition-auth"
        model_name = "e2e-temp-model-status"
        sa_name = "e2e-status-transition-sa"
    
        try:
            _create_sa_token(sa_name, namespace=MODEL_NAMESPACE)
            sa_user = _sa_to_user(sa_name, namespace=MODEL_NAMESPACE)
    
            # Create a temporary model
            _create_test_maas_model(model_name, llmis_name=MODEL_REF, namespace=MODEL_NAMESPACE)
            _wait_reconcile()
    
            # Create auth policy and subscription for the model
            _create_test_auth_policy(auth_name, model_name, users=[sa_user])
            _create_test_subscription(subscription_name, model_name, users=[sa_user])
    
&gt;           _wait_for_maas_auth_policy_phase(auth_name)

test/e2e/tests/test_subscription.py:2136: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

name = 'e2e-status-transition-auth', expected_phase = 'Active'
namespace = 'models-as-a-service', timeout = 60, require_auth_policies = False
require_enforced = True

    def _wait_for_maas_auth_policy_phase(name, expected_phase="Active", namespace=None, timeout=60,
                                    require_auth_policies=False, require_enforced=True):
        """Wait for MaaSAuthPolicy to reach a specific phase.
    
        Args:
            name: Name of the MaaSAuthPolicy
            expected_phase: Phase to wait for (default: "Active")
            namespace: Namespace (defaults to _ns())
            timeout: Maximum wait time in seconds (default: 60)
            require_auth_policies: If True, requires authPolicies to be populated (default: False).
                                   Keep False for gateway-only AuthPolicy reconciliation.
            require_enforced: If True (default):
                - with require_auth_policies=True: all status.authPolicies entries must be ready
                - with require_auth_policies=False and expected_phase Active: also wait for the
                  gateway Kuadrant AuthPolicy (maas-gateway-auth) to be Accepted+Enforced
    
        Returns:
            The auth policy CR dict when the expected phase is reached
    
        Raises:
            TimeoutError: If MaaSAuthPolicy doesn't reach expected phase within timeout
        """
        namespace = namespace or _ns()
        deadline = time.time() + timeout
        log.info(f"Waiting for MaaSAuthPolicy {name} to reach phase '{expected_phase}' (timeout: {timeout}s)...")
    
        while time.time() &lt; deadline:
            cr = _get_cr("maasauthpolicy", name, namespace)
            if cr:
                status = cr.get("status", {})
                phase = status.get("phase")
                auth_policies = status.get("authPolicies", [])
    
                if phase == expected_phase:
                    # No per-model auth policies required — phase match is sufficient for the CR,
                    # but gateway-only mode still needs Kuadrant Enforced before HTTP calls.
                    # Callers that intentionally stop Kuadrant (e.g. TRLP degraded tests) must
                    # pass require_enforced=False — Enforced cannot become True while Kuadrant is down.
                    if not require_auth_policies:
                        if require_enforced and expected_phase == "Active":
                            # Keep a floor so a slow phase wait does not starve Kuadrant Enforced.
                            # AuthConfig backlog after policy churn often needs the full enforced timeout.
                            remaining = max(GATEWAY_ENFORCED_TIMEOUT, int(deadline - time.time()))
                            _wait_for_gateway_auth_enforced(timeout=remaining)
                        log.info(f"MaaSAuthPolicy {name} reached phase '{expected_phase}'")
                        return cr
    
                    # Auth policies required — check they exist
                    if len(auth_policies) &gt; 0:
                        if require_enforced:
                            all_enforced = all(
                                ap.get("ready") is True
                                for ap in auth_policies
                            )
                            if all_enforced:
                                log.info(f"MaaSAuthPolicy {name} reached phase '{expected_phase}' and all enforced")
                                return cr
                        else:
                            log.info(f"MaaSAuthPolicy {name} reached phase '{expected_phase}' with {len(auth_policies)} auth policy status(es)")
                            return cr
    
                log.debug(f"MaaSAuthPolicy {name}: phase={phase}, authPolicies={len(auth_policies)}")
            time.sleep(2)
    
        # Timeout - return current state for debugging
        cr = _get_cr("maasauthpolicy", name, namespace)
        status = cr.get("status", {}) if cr else {}
&gt;       raise TimeoutError(
            f"MaaSAuthPolicy {name} did not reach phase '{expected_phase}' within {timeout}s "
            f"(current: phase={status.get('phase')}, authPolicies={len(status.get('authPolicies', []))})"
        )
E       TimeoutError: MaaSAuthPolicy e2e-status-transition-auth did not reach phase 'Active' within 60s (current: phase=Pending, authPolicies=0)

test/e2e/tests/test_helper.py:1134: TimeoutError</failure></testcase><testcase classname="test.e2e.tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_degraded_healthy_model_allows_inference" time="15.217" /><testcase classname="test.e2e.tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_failed_subscription_blocks_inference" time="15.502" /><testcase classname="test.e2e.tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_models_endpoint_with_degraded_subscription_api_key" time="15.206" /><testcase classname="test.e2e.tests.test_subscription.TestDegradedSubscriptionFiltering" name="test_models_endpoint_with_degraded_subscription_kube_token" time="15.184" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_single_subscription_auto_select" time="16.400" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_explicit_subscription_header" time="8.711" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_empty_subscription_header_value" time="4.380" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_models_filtered_by_subscription" time="4.747" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_deduplication_same_model_multiple_refs" time="9.140" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_different_modelrefs_same_model_id" time="74.952" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_multiple_distinct_models_in_subscription" time="15.780" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_user_token_returns_all_models" time="14.964" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_user_token_with_subscription_header_filters" time="9.016" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_empty_model_list" time="11.246" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_response_schema_matches_openapi" time="4.400" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_model_metadata_preserved" time="4.391" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_scoped_to_subscription" time="9.162" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_with_deleted_subscription_403" time="13.189" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_with_inaccessible_subscription_403" time="9.618" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_invalid_subscription_header_403" time="9.018" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_access_denied_to_subscription_403" time="9.664" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_api_key_ignores_subscription_header" time="14.139" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_multiple_api_keys_different_subscriptions" time="16.375" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_service_account_token_multiple_subs_no_header" time="14.767" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_service_account_token_multiple_subs_with_header" time="16.974" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_unauthenticated_request_401" time="0.054" /><testcase classname="test.e2e.tests.test_models_endpoint.TestModelsEndpoint" name="test_central_models_endpoint_exempt_from_rate_limiting" time="21.406" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelDiscovery" name="test_maasmodelref_created" time="11.741" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_httproute" time="0.116" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelDiscovery" name="test_reconciler_created_backend_service" time="0.106" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelAuth" name="test_invalid_key_returns_401" time="0.050" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelAuth" name="test_no_key_returns_401" time="0.029" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelEgress" name="test_request_forwarded_returns_200" time="0.157" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelCleanup" name="test_delete_removes_httproute" time="12.629" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelPathRouting" name="test_wrong_path_returns_not_found" time="0.033" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelBodyRouting" name="test_correct_model_in_body_succeeds" time="0.132" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelBodyRouting" name="test_wrong_model_in_body_does_not_error" time="0.082" /><testcase classname="test.e2e.tests.test_external_models.TestExternalModelBodyRouting" name="test_missing_model_in_body_does_not_error" time="1.157" /><testcase classname="test.e2e.tests.test_tenant.TestTenantLifecycle" name="test_tenant_ready_and_phase_healthy" time="184.538"><failure message="AssertionError: MaasTenantConfig Ready did not become True in time.&#10;assert None is not None">self = &lt;test_tenant.TestTenantLifecycle object at 0x7f8f1a58ed60&gt;

    def test_tenant_ready_and_phase_healthy(self):
        st = _wait_tenant_ready()
&gt;       assert st is not None, "MaasTenantConfig Ready did not become True in time."
E       AssertionError: MaasTenantConfig Ready did not become True in time.
E       assert None is not None

test/e2e/tests/test_tenant.py:115: AssertionError</failure></testcase><testcase classname="test.e2e.tests.test_tenant.TestTenantLifecycle" name="test_payload_processing_deployed_with_active_tenant" time="184.310"><failure message="AssertionError: MaasTenantConfig not Ready; skip workload checks.&#10;assert None is not None">self = &lt;test_tenant.TestTenantLifecycle object at 0x7f8f1a58e640&gt;

    def test_payload_processing_deployed_with_active_tenant(self):
        """Default-tenant MaasTenantConfig should reconcile legacy unsuffixed IPP Deployments."""
        st = _wait_tenant_ready()
&gt;       assert st is not None, "MaasTenantConfig not Ready; skip workload checks."
E       AssertionError: MaasTenantConfig not Ready; skip workload checks.
E       assert None is not None

test/e2e/tests/test_tenant.py:125: AssertionError</failure></testcase><testcase classname="test.e2e.tests.test_tenant.TestTenantContract" name="test_status_has_phase_and_conditions" time="0.122" /><testcase classname="test.e2e.tests.test_tenant.TestTenantContract" name="test_spec_is_well_formed" time="0.112" /><testcase classname="test.e2e.tests.test_tenant.TestTenantContract" name="test_conditions_use_kubernetes_metav1_shape" time="0.110" /><testcase classname="test.e2e.tests.test_tenant.TestTenantNoFalseOwnership" name="test_maas_user_crs_not_owned_by_tenant" time="0.340" /><testcase classname="test.e2e.tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_default_aitenant_bootstraps_maas_tenant_config_without_gateway_mutation" time="240.865"><failure message="AssertionError: aitenant/models-as-a-service in ai-tenants did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'AITenant', 'metadata': {'creationTimestamp': '2026-07-31T21:37:37Z', 'finalizers': ['maas.opendatahub.io/aitenant-cleanup'], 'generation': 1, 'name': 'models-as-a-service', 'namespace': 'ai-tenants', 'ownerReferences': [{'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'Config', 'name': 'default', 'uid': '972e90c0-1e9a-462d-8ed2-277ea7b1f44b'}], 'resourceVersion': '21748', 'uid': '46eb8cf7-feaf-47f6-9a06-bbd188f7f247'}, 'spec': {'gateway': {'name': 'maas-default-gateway'}}, 'status': {'conditions': [{'lastTransitionTime': '2026-07-31T21:37:39Z', 'message': 'waiting for MaasTenantConfig to report Ready', 'observedGeneration': 1, 'reason': 'TenantConfigNotReady', 'status': 'False', 'type': 'Ready'}], 'gatewayRef': {'name': 'maas-default-gateway', 'namespace': 'openshift-ingress'}, 'phase': 'Pending', 'tenantNamespace': 'models-as-a-service'}}">self = &lt;test_aitenant_lifecycle.TestAITenantLifecycle object at 0x7f8f1a0f6100&gt;

    def test_default_aitenant_bootstraps_maas_tenant_config_without_gateway_mutation(self):
&gt;       aitenant = _wait_for_json(
            AITENANT_KIND,
            DEFAULT_AITENANT_NAME,
            AITENANT_NAMESPACE,
            predicate=_aitenant_ready,
            timeout=240,
        )

test/e2e/tests/test_aitenant_lifecycle.py:297: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'aitenant', name = 'models-as-a-service', namespace = 'ai-tenants'

    def _wait_for_json(kind, name, namespace=None, *, predicate=None, timeout=180, interval=5):
        deadline = time.time() + timeout
        last_obj = None
        while time.time() &lt; deadline:
            obj = _get_json_or_none(kind, name, namespace)
            if obj is not None:
                last_obj = obj
                if predicate is None or predicate(obj):
                    return obj
            time.sleep(interval)
&gt;       raise AssertionError(f"{kind}/{name} in {namespace or '&lt;cluster&gt;'} did not satisfy condition. Last object: {last_obj}")
E       AssertionError: aitenant/models-as-a-service in ai-tenants did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'AITenant', 'metadata': {'creationTimestamp': '2026-07-31T21:37:37Z', 'finalizers': ['maas.opendatahub.io/aitenant-cleanup'], 'generation': 1, 'name': 'models-as-a-service', 'namespace': 'ai-tenants', 'ownerReferences': [{'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'Config', 'name': 'default', 'uid': '972e90c0-1e9a-462d-8ed2-277ea7b1f44b'}], 'resourceVersion': '21748', 'uid': '46eb8cf7-feaf-47f6-9a06-bbd188f7f247'}, 'spec': {'gateway': {'name': 'maas-default-gateway'}}, 'status': {'conditions': [{'lastTransitionTime': '2026-07-31T21:37:39Z', 'message': 'waiting for MaasTenantConfig to report Ready', 'observedGeneration': 1, 'reason': 'TenantConfigNotReady', 'status': 'False', 'type': 'Ready'}], 'gatewayRef': {'name': 'maas-default-gateway', 'namespace': 'openshift-ingress'}, 'phase': 'Pending', 'tenantNamespace': 'models-as-a-service'}}

test/e2e/tests/test_aitenant_lifecycle.py:114: AssertionError</failure></testcase><testcase classname="test.e2e.tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_rejected_outside_ai_tenants_namespace" time="6.640" /><testcase classname="test.e2e.tests.test_aitenant_lifecycle.TestAITenantLifecycle" name="test_aitenant_create_bootstrap_resources" time="194.842"><failure message="AssertionError: aitenant/e2e-ait-8ef214f7 in ai-tenants did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'AITenant', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{&quot;apiVersion&quot;:&quot;maas.opendatahub.io/v1alpha1&quot;,&quot;kind&quot;:&quot;AITenant&quot;,&quot;metadata&quot;:{&quot;annotations&quot;:{},&quot;name&quot;:&quot;e2e-ait-8ef214f7&quot;,&quot;namespace&quot;:&quot;ai-tenants&quot;},&quot;spec&quot;:{}}\n'}, 'creationTimestamp': '2026-07-31T22:08:17Z', 'finalizers': ['maas.opendatahub.io/aitenant-cleanup'], 'generation': 1, 'name': 'e2e-ait-8ef214f7', 'namespace': 'ai-tenants', 'resourceVersion': '52155', 'uid': '11633a20-3706-457a-9fc8-89cd2dad7ac2'}, 'spec': {}, 'status': {'conditions': [{'lastTransitionTime': '2026-07-31T22:08:18Z', 'message': 'waiting for MaasTenantConfig to report Ready', 'observedGeneration': 1, 'reason': 'TenantConfigNotReady', 'status': 'False', 'type': 'Ready'}], 'gatewayRef': {'name': 'e2e-ait-8ef214f7', 'namespace': 'openshift-ingress'}, 'phase': 'Pending', 'tenantNamespace': 'ai-tenant-e2e-ait-8ef214f7'}}">self = &lt;test_aitenant_lifecycle.TestAITenantLifecycle object at 0x7f8f1a0f64c0&gt;

    def test_aitenant_create_bootstrap_resources(self):
        case = _new_aitenant_case()
    
        try:
            _apply_gateway_fixture(case)
            _apply_aitenant(case)
&gt;           _assert_aitenant_bootstrap_resources(case)

test/e2e/tests/test_aitenant_lifecycle.py:423: 
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
test/e2e/tests/test_aitenant_lifecycle.py:206: in _assert_aitenant_bootstrap_resources
    aitenant = _wait_for_json(
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

kind = 'aitenant', name = 'e2e-ait-8ef214f7', namespace = 'ai-tenants'

    def _wait_for_json(kind, name, namespace=None, *, predicate=None, timeout=180, interval=5):
        deadline = time.time() + timeout
        last_obj = None
        while time.time() &lt; deadline:
            obj = _get_json_or_none(kind, name, namespace)
            if obj is not None:
                last_obj = obj
                if predicate is None or predicate(obj):
                    return obj
            time.sleep(interval)
&gt;       raise AssertionError(f"{kind}/{name} in {namespace or '&lt;cluster&gt;'} did not satisfy condition. Last object: {last_obj}")
E       AssertionError: aitenant/e2e-ait-8ef214f7 in ai-tenants did not satisfy condition. Last object: {'apiVersion': 'maas.opendatahub.io/v1alpha1', 'kind': 'AITenant', 'metadata': {'annotations': {'kubectl.kubernetes.io/last-applied-configuration': '{"apiVersion":"maas.opendatahub.io/v1alpha1","kind":"AITenant","metadata":{"annotations":{},"name":"e2e-ait-8ef214f7","namespace":"ai-tenants"},"spec":{}}\n'}, 'creationTimestamp': '2026-07-31T22:08:17Z', 'finalizers': ['maas.opendatahub.io/aitenant-cleanup'], 'generation': 1, 'name': 'e2e-ait-8ef214f7', 'namespace': 'ai-tenants', 'resourceVersion': '52155', 'uid': '11633a20-3706-457a-9fc8-89cd2dad7ac2'}, 'spec': {}, 'status': {'conditions': [{'lastTransitionTime': '2026-07-31T22:08:18Z', 'message': 'waiting for MaasTenantConfig to report Ready', 'observedGeneration': 1, 'reason': 'TenantConfigNotReady', 'status': 'False', 'type': 'Ready'}], 'gatewayRef': {'name': 'e2e-ait-8ef214f7', 'namespace': 'openshift-ingress'}, 'phase': 'Pending', 'tenantNamespace': 'ai-tenant-e2e-ait-8ef214f7'}}

test/e2e/tests/test_aitenant_lifecycle.py:114: AssertionError</failure></testcase></testsuite></testsuites>