diff --git a/metropolis/pkg/pki/BUILD.bazel b/metropolis/pkg/pki/BUILD.bazel
index 547d733..c215ce2 100644
--- a/metropolis/pkg/pki/BUILD.bazel
+++ b/metropolis/pkg/pki/BUILD.bazel
@@ -5,7 +5,6 @@
     srcs = [
         "ca.go",
         "certificate.go",
-        "testhelpers.go",
         "x509.go",
     ],
     importpath = "source.monogon.dev/metropolis/pkg/pki",
diff --git a/metropolis/pkg/pki/testhelpers.go b/metropolis/pkg/pki/testhelpers.go
deleted file mode 100644
index f975967..0000000
--- a/metropolis/pkg/pki/testhelpers.go
+++ /dev/null
@@ -1,65 +0,0 @@
-package pki
-
-import (
-	"context"
-	"crypto/tls"
-	"crypto/x509"
-	"testing"
-)
-
-// EphemeralClusterCredentials returns a pair of node and manager
-// tls.Certificates signed by a CA certificate.
-//
-// All of these are ephemeral, ie. not stored anywhere - including the CA
-// certificate. This function is for use by tests which want to bring up a
-// minimum set of PKI credentials for a fake Metropolis cluster.
-func EphemeralClusterCredentials(t *testing.T) (node, manager tls.Certificate, ca *x509.Certificate) {
-	ctx := context.Background()
-
-	ns := Namespaced("unused")
-	caCert := Certificate{
-		Namespace: &ns,
-		Issuer:    SelfSigned,
-		Template:  CA("test cluster ca"),
-		Mode:      CertificateEphemeral,
-	}
-	caBytes, err := caCert.Ensure(ctx, nil)
-	if err != nil {
-		t.Fatalf("Could not ensure CA certificate: %v", err)
-	}
-	ca, err = x509.ParseCertificate(caBytes)
-	if err != nil {
-		t.Fatalf("Could not parse new CA certificate: %v", err)
-	}
-
-	nodeCert := Certificate{
-		Namespace: &ns,
-		Issuer:    &caCert,
-		Template:  Server([]string{"test-server"}, nil),
-		Mode:      CertificateEphemeral,
-	}
-	nodeBytes, err := nodeCert.Ensure(ctx, nil)
-	if err != nil {
-		t.Fatalf("Could not ensure node certificate: %v", err)
-	}
-	node = tls.Certificate{
-		Certificate: [][]byte{nodeBytes},
-		PrivateKey:  nodeCert.PrivateKey,
-	}
-
-	managerCert := Certificate{
-		Namespace: &ns,
-		Issuer:    &caCert,
-		Template:  Client("owner", nil),
-		Mode:      CertificateEphemeral,
-	}
-	managerBytes, err := managerCert.Ensure(ctx, nil)
-	if err != nil {
-		t.Fatalf("Could not ensure manager certificate: %v", err)
-	}
-	manager = tls.Certificate{
-		Certificate: [][]byte{managerBytes},
-		PrivateKey:  managerCert.PrivateKey,
-	}
-	return
-}
diff --git a/metropolis/pkg/supervisor/supervisor_testhelpers.go b/metropolis/pkg/supervisor/supervisor_testhelpers.go
index 711ed00..b2812c2 100644
--- a/metropolis/pkg/supervisor/supervisor_testhelpers.go
+++ b/metropolis/pkg/supervisor/supervisor_testhelpers.go
@@ -49,6 +49,7 @@
 	logtree.PipeAllToStderr(t, lt)
 
 	New(ctx, func(ctx context.Context) error {
+		Logger(ctx).Infof("Starting test %s...", t.Name())
 		if err := r(ctx); err != nil && !errors.Is(err, ctx.Err()) {
 			t.Errorf("Supervised runnable in harness returned error: %v", err)
 		}
