2026-06-29T22:15:38Z TRC kyverno/pkg/version/version.go:49 > version hash=--- logger=setup/version v=2 version=1.25.8 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > add_dir_header=false logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > admissionReports=false logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > allowInsecureRegistry=false logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > alsologtostderr=false logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > autoDeleteWebhooks=false logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > autoUpdateWebhooks=true logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > backgroundServiceAccountName=system:serviceaccount:konflux-kyverno:kyverno-background-controller logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > caSecretName=konflux-kyverno-svc.konflux-kyverno.svc.kyverno-tls-ca logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > cleanupServerPort=9443 logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > clientRateLimitBurst=200 logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > clientRateLimitQPS=100 logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > controllerRuntimeMetricsAddress=:8080 logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > crdWatcher=false logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > disableLogColor=false logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > disableMetrics=false logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > dumpPatches= logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > dumpPayload=false logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > enableConfigMapCaching=true logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > enableDeferredLoading= logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > enablePolicyException=false logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > enableReporting= logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > enableTracing=false logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > enableTuf=false logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > eventsRateLimitBurst=2000 logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > eventsRateLimitQPS=1000 logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > exceptionNamespace= logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > forceFailurePolicyIgnore= logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > generateMutatingAdmissionPolicy= logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > generateValidatingAdmissionPolicy= logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > imagePullSecrets= logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheEnabled=true logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheMaxSize=1000 logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheTTLDuration=1h0m0s logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > kubeconfig= logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > leaderElectionRetryPeriod=26s logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > log_backtrace_at=:0 logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > log_dir= logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > log_file= logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > log_file_max_size=1800 logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag loggingFormat=text v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag loggingtsFormat=default v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag logtostderr=true v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAPICallResponseLength=2000000 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAdmissionReports=1000 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAuditCapacity=1000 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAuditWorkers=8 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxQueuedEvents=1000 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag metricsPort=8000 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag omitEvents=PolicyApplied,PolicySkipped v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag one_output=false v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag otelCollector=opentelemetrycollector.kyverno.svc.cluster.local v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag otelConfig=prometheus v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profile=false v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profileAddress= v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profilePort=6060 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag protectManagedResources= v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag registryCredentialHelpers=default,google,amazon,azure,github v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag renewBefore=360h0m0s v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag reportsServiceAccountName= v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag resyncPeriod=15m0s v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag serverIP= v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag servicePort=443 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag skip_headers=false v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag skip_log_headers=false v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag stderrthreshold=2 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tlsSecretName=konflux-kyverno-svc.konflux-kyverno.svc.kyverno-tls-pair v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingAddress= v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingCreds= v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingPort=4317 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag transportCreds= v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufMirror=https://tuf-repo-cdn.sigstore.dev v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufRoot= v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufRootRaw= v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 vmodule= 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookRegistrationTimeout=2m0s 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookServerPort=9443 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookTimeout=10 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/maxprocs.go:12 > setup maxprocs... logger=setup/maxprocs v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/signal.go:16 > setup signals... logger=setup/signals v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/kube-client qps=100 v=2 2026-06-29T22:15:38Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=true feature=InOrderInformers logger=klog v=1 2026-06-29T22:15:38Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=WatchListClient logger=klog v=1 2026-06-29T22:15:38Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=ClientsAllowCBOR logger=klog v=1 2026-06-29T22:15:38Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=ClientsPreferCBOR logger=klog v=1 2026-06-29T22:15:38Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=InformerResourceVersion logger=klog v=1 2026-06-29T22:15:38Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/metrics.go:18 > setup metrics... collector=opentelemetrycollector.kyverno.svc.cluster.local creds= logger=setup/metrics otel=prometheus port=8000 v=2 2026-06-29T22:15:38Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:417 > defaultRegistry configured defaultRegistry=docker.io logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:433 > enableDefaultRegistryMutation configured enableDefaultRegistryMutation=true logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:442 > excludedGroups configured excludeGroups=["system:nodes"] includeGroups=[] logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:447 > excludeUsernames not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:455 > excludeRoles not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:463 > excludeClusterRoles not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:479 > generateSuccessEvents configured generateSuccessEvents=false logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:493 > webhooks configured logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 webhooks="{\"namespaceSelector\":{\"matchExpressions\":[{\"key\":\"kubernetes.io/metadata.name\",\"operator\":\"NotIn\",\"values\":[\"kube-system\"]},{\"key\":\"kubernetes.io/metadata.name\",\"operator\":\"NotIn\",\"values\":[\"konflux-kyverno\"]}],\"matchLabels\":null}}" 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:507 > webhookAnnotations configured logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 webhookAnnotations="{\"admissions.enforcer/disabled\":\"true\"}" 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:513 > webhookLabels not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:527 > matchConditions not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:548 > enableDefaultRegistryMutation configured enableDefaultRegistryMutation=true logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T22:15:38Z TRC kyverno/pkg/config/config.go:563 > maxContextSize not set, using default default=2097152 logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/registry.go:18 > setup registry client... insecure=false logger=setup/registry-client secrets= v=2 2026-06-29T22:15:38Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/imageverifycache.go:10 > setup image verify cache... enabled=true logger=setup/image-verify-cache maxsize=1000 ttl=1h0m0s v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/kube-client qps=100 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/client.go:60 > create kyverno client... burst=200 kubeconfig= logger=setup/kyverno-client qps=100 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/client.go:68 > create dynamic client... burst=200 kubeconfig= logger=setup/dynamic-client qps=100 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/client.go:84 > create apiserver client... burst=200 kubeconfig= logger=setup/apiserver-client qps=100 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/client.go:76 > create metadata client... burst=200 kubeconfig= logger=setup/metadata-client qps=100 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/client.go:92 > create the kyverno dynamic client... burst=200 kubeconfig= logger=setup/d-client qps=100 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/client.go:100 > create the events client... burst=200 kubeconfig= logger=setup/events-client qps=100 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/events-client/kube-client qps=100 v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/reporting.go:13 > setting up reporting... enableReporting= generate=false imageVerify=false logger=setup/setup-reporting mutate=false mutateExisiting=false v=2 validate=false 2026-06-29T22:15:38Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-06-29T22:15:38Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-06-29T22:15:38Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Deployment v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/engine.go:65 > setup exception selector... enablePolicyException=false exceptionNamespace= logger=setup/exception-selector v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/engine.go:94 > setup config map resolver... enableConfigMapCaching=true logger=setup/configmap-resolver v=2 2026-06-29T22:15:38Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-06-29T22:15:38Z TRC kyverno/cmd/internal/engine.go:46 > setup engine... logger=setup/engine v=2 2026-06-29T22:15:38Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterPolicy v=2 2026-06-29T22:15:38Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Policy v=2 2026-06-29T22:15:38Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Deployment v=2 2026-06-29T22:15:38Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2alpha1.GlobalContextEntry v=2 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/metrics/server/server.go:208 > Starting metrics server logger=controller-runtime/metrics v=0 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/metrics/server/server.go:247 > Serving metrics server bindAddress=:8080 logger=controller-runtime/metrics secure=false v=0 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy source="kind source: *v1alpha1.MutatingPolicy" v=0 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy source="kind source: *v1alpha1.ValidatingPolicy" v=0 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy source="kind source: *v1alpha1.ImageValidatingPolicy" v=0 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.GeneratingPolicy v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Namespace v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2.UpdateRequest v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterRoleBinding v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.PolicyException v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.MutatingPolicy v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ValidatingPolicy v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ImageValidatingPolicy v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.RoleBinding v=2 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/leaderelection/leaderelection.go:257 > attempting to acquire leader lease konflux-kyverno/kyverno... logger=klog v=0 2026-06-29T22:15:39Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup name=kyverno-events v=2 workers=3 2026-06-29T22:15:39Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup name=global-context v=2 workers=1 2026-06-29T22:15:39Z TRC kyverno/pkg/event/controller.go:106 > start logger=EventGenerator v=2 2026-06-29T22:15:39Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/controllers name=policycache-controller v=2 workers=3 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy v=0 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy v=0 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy v=0 worker count=1 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy v=0 worker count=1 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy v=0 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy v=0 worker count=1 2026-06-29T22:15:39Z INF cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/leaderelection/leaderelection.go:271 > successfully acquired lease konflux-kyverno/kyverno logger=klog v=0 2026-06-29T22:15:39Z TRC kyverno/pkg/leaderelection/leaderelection.go:83 > started leading id=kyverno-admission-controller-5cbb799dc8-8gb7g logger=setup/leader-election v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Policy v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.PolicyException v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ValidatingPolicy v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterPolicy v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingAdmissionPolicyBinding v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.MutatingWebhookConfiguration v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Lease v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2.PolicyException v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ImageValidatingPolicy v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingWebhookConfiguration v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.MutatingPolicy v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.GeneratingPolicy v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingAdmissionPolicy v=2 2026-06-29T22:15:39Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterRole v=2 2026-06-29T22:15:39Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=exception-webhook-controller v=2 workers=1 2026-06-29T22:15:39Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=celexception-webhook-controller v=2 workers=1 2026-06-29T22:15:39Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=webhook-controller v=2 workers=2 2026-06-29T22:15:39Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=certmanager-controller v=2 workers=1 2026-06-29T22:15:39Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=status-controller v=2 workers=3 2026-06-29T22:15:39Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=global-context-webhook-controller v=2 workers=1 2026-06-29T22:15:39Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=admissionpolicy-generator v=2 workers=2 2026-06-29T22:15:39Z TRC kyverno/pkg/utils/controller/run.go:58 > starting ... logger=admissionpolicy-generator v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=integration-init-ns-integration uid=4e613bc4-16a6-432e-8f56-d515f1201afb v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=integration-init-ns-integration type=ClusterPolicy v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-rbcm type=ClusterPolicy v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-rbcm uid=3f7641be-1d73-488d-898a-d5b0b1ce1826 v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-olm uid=b58a05e1-bfa2-4716-afc9-b7d169651d13 v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-olm type=ClusterPolicy v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpingress type=ClusterPolicy v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpingress uid=ec7a03a6-51c3-4899-bba4-27db8a36e57b v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=init-ns-kubearchiveconfig uid=b55489ed-6985-4109-9fcb-f521c25440c2 v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=init-ns-kubearchiveconfig type=ClusterPolicy v=2 2026-06-29T22:19:34Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:34 http: TLS handshake error from 10.130.0.2:39870: EOF logger=webhooks/server v=0 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpmonitoring uid=032aa92c-1b90-45cf-9d9a-adc4edfccfae v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpconsole uid=ca9880b8-e10c-488a-8b30-b1a10bc64d9c v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpmonitoring type=ClusterPolicy v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpconsole type=ClusterPolicy v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-samenamespace type=ClusterPolicy v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-samenamespace uid=56dde340-b03d-4597-b880-ae6763004750 v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-generate-konflux-viewer-access uid=4f899e54-e667-42e3-816c-dd0c9d6fa4bc v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-generate-konflux-viewer-access type=ClusterPolicy v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-validate-restrict-binding-sysauth-releng type=ClusterPolicy v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-validate-restrict-binding-sysauth-releng uid=5038cd5f-c492-4512-ab27-47e948ff571f v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-validate-restrict-binding-system-authenticated uid=64d4bd5f-f8d7-403b-8478-10a73d60863b v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-validate-restrict-binding-system-authenticated type=ClusterPolicy v=2 2026-06-29T22:19:34Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"konflux-rbac-validate-restrict-binding-sysauth-releng\": the object has been modified; please apply your changes to the latest version and try again" konflux-rbac-validate-restrict-binding-sysauth-releng=status 2026-06-29T22:19:34Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"konflux-rbac-validate-restrict-binding-system-authenticated\": the object has been modified; please apply your changes to the latest version and try again" konflux-rbac-validate-restrict-binding-system-authenticated=status 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=restrict-docker-io-images type=ClusterPolicy v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=restrict-docker-io-images uid=1b52bbc0-04de-43fd-9b83-39fb0d64e5a6 v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=restrict-binding-system-groups uid=b12071df-87fe-47f6-a018-ceb63b6657cb v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=restrict-binding-system-groups type=ClusterPolicy v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=tekton-taskrun-resource-policy uid=c678b008-7558-4776-aa33-b56ad64612cf v=2 2026-06-29T22:19:34Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=tekton-taskrun-resource-policy type=ClusterPolicy v=2 2026-06-29T22:19:34Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"restrict-docker-io-images\": the object has been modified; please apply your changes to the latest version and try again" restrict-docker-io-images=status 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=DaemonSet" gvr="apps/v1, Resource=daemonsets" kind=DaemonSet logger=webhooks/resource/validate name=vector namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/DaemonSet/vector resource.gvk="apps/v1, Kind=DaemonSet" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=a22faba4-1aca-4cd2-b5dd-bc4939b1c670 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:daemon-set-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=vector-p6bkd namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/vector-p6bkd resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=22feaba7-948b-4602-ac05-8a6ec5dd6618 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=07fc9a07-d683-419b-83dd-03affc8704d0"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"dff247c2-b3d4-48f7-b15e-9e3e165be6c7","username":"system:serviceaccount:kube-system:daemon-set-controller"} v=2 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.129.0.2:57692: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:daemon-set-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=vector-2qgzt namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/vector-2qgzt resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=11e427c3-7079-4d5d-8544-cf77e922ddc2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=07fc9a07-d683-419b-83dd-03affc8704d0"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"dff247c2-b3d4-48f7-b15e-9e3e165be6c7","username":"system:serviceaccount:kube-system:daemon-set-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:daemon-set-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=vector-5r8gz namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/vector-5r8gz resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=834dda45-f66e-40db-83b5-8fc6ee6c597a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=07fc9a07-d683-419b-83dd-03affc8704d0"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"dff247c2-b3d4-48f7-b15e-9e3e165be6c7","username":"system:serviceaccount:kube-system:daemon-set-controller"} v=2 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.129.0.2:57700: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=grafana namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Deployment/grafana resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=834f30ab-14e6-48ab-b41f-1723d74f52c0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=loki-gateway namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Deployment/loki-gateway resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=ddd634e7-58ad-4b5c-8281-7790721d4b64 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=loki-query-frontend namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Deployment/loki-query-frontend resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=3f200492-49ba-4a29-a958-fb53c5cc0eac user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=loki-query-scheduler namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Deployment/loki-query-scheduler resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=5da24f45-e408-4881-974f-9e133a5b9abc user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.130.0.2:39916: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=loki-distributor namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Deployment/loki-distributor resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=5fe5da22-a37b-4536-aca6-ab475fe96649 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=loki-minio namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Deployment/loki-minio resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=903d28d2-51ca-42b4-866d-1e217ebeb8ed user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.129.0.2:57708: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=loki-querier namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Deployment/loki-querier resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=cef92705-5892-4bdb-9594-efcbae078f68 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=grafana-c8755fcdd-7hc96 namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/grafana-c8755fcdd-7hc96 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a53c3711-f391-4d38-ac64-968cf661c122 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8c90360d-0767-497f-9234-2cce34f8eedf"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.128.0.2:37658: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.128.0.2:37666: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=loki-gateway-7f8d55d955-qmwmb namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/loki-gateway-7f8d55d955-qmwmb resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=be7d6764-abde-4a7f-8d21-ca81cee5a0de user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8c90360d-0767-497f-9234-2cce34f8eedf"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.128.0.2:37678: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.130.0.2:39926: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=loki-query-frontend-686ccc7ffd-sddth namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/loki-query-frontend-686ccc7ffd-sddth resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1b0837c8-cd4d-4a39-9828-851cde88861f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8c90360d-0767-497f-9234-2cce34f8eedf"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=loki-query-scheduler-d94f58657-c6g5m namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/loki-query-scheduler-d94f58657-c6g5m resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=bbd52d86-5221-488f-a0c0-71cd2d3f37ae user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8c90360d-0767-497f-9234-2cce34f8eedf"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.129.0.2:57724: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.128.0.2:37688: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=loki-distributor-7696f46544-dwc99 namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/loki-distributor-7696f46544-dwc99 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=cb1bea01-1379-43e9-b7e3-e145abee1354 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8c90360d-0767-497f-9234-2cce34f8eedf"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=loki-minio-56ffc7f4dd-d2gk2 namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/loki-minio-56ffc7f4dd-d2gk2 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c6b24f3d-c80c-4359-8c83-90bf2e003423 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8c90360d-0767-497f-9234-2cce34f8eedf"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=StatefulSet" gvr="apps/v1, Resource=statefulsets" kind=StatefulSet logger=webhooks/resource/validate name=loki-index-gateway namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/StatefulSet/loki-index-gateway resource.gvk="apps/v1, Kind=StatefulSet" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=69e11746-1736-4439-a5b2-e0a681d85496 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.128.0.2:37702: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=loki-querier-f94f578b6-775n6 namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/loki-querier-f94f578b6-775n6 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=bf5adad1-a7e3-46e7-8792-93b12c9c9027 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8c90360d-0767-497f-9234-2cce34f8eedf"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=StatefulSet" gvr="apps/v1, Resource=statefulsets" kind=StatefulSet logger=webhooks/resource/validate name=loki-compactor namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/StatefulSet/loki-compactor resource.gvk="apps/v1, Kind=StatefulSet" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=325e64a5-32e8-4bf1-b610-851aa002c05d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=StatefulSet" gvr="apps/v1, Resource=statefulsets" kind=StatefulSet logger=webhooks/resource/validate name=loki-chunks-cache namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/StatefulSet/loki-chunks-cache resource.gvk="apps/v1, Kind=StatefulSet" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=5f26e8b1-fe89-4102-9a3b-59ac74b9b35a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=StatefulSet" gvr="apps/v1, Resource=statefulsets" kind=StatefulSet logger=webhooks/resource/validate name=loki-results-cache namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/StatefulSet/loki-results-cache resource.gvk="apps/v1, Kind=StatefulSet" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=8e33c964-4454-430b-ad97-8f0968eb34f9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=StatefulSet" gvr="apps/v1, Resource=statefulsets" kind=StatefulSet logger=webhooks/resource/validate name=loki-ingester namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/StatefulSet/loki-ingester resource.gvk="apps/v1, Kind=StatefulSet" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=178c266d-ee3a-4c53-9f75-6e27ec1f18a3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.130.0.2:39946: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:statefulset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=loki-index-gateway-0 namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/loki-index-gateway-0 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=44fd8095-f62b-4817-9e47-85bf466d94d3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=b4ad89e7-96a8-4753-8fdb-2d5ce5cfa75f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"87b49f8a-01f0-4e50-bf1f-bf78cd70ef4e","username":"system:serviceaccount:kube-system:statefulset-controller"} v=2 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.130.0.2:39958: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:38 http: TLS handshake error from 10.128.0.2:37718: EOF logger=webhooks/server v=0 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:statefulset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=loki-compactor-0 namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/loki-compactor-0 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4bace3f2-2e60-4c20-b85a-2bbac32c13b0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=b4ad89e7-96a8-4753-8fdb-2d5ce5cfa75f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"87b49f8a-01f0-4e50-bf1f-bf78cd70ef4e","username":"system:serviceaccount:kube-system:statefulset-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:statefulset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=loki-chunks-cache-0 namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/loki-chunks-cache-0 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a8f52c19-356d-45b8-a1bc-ce249dc8b89e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=b4ad89e7-96a8-4753-8fdb-2d5ce5cfa75f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"87b49f8a-01f0-4e50-bf1f-bf78cd70ef4e","username":"system:serviceaccount:kube-system:statefulset-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:statefulset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=loki-results-cache-0 namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/loki-results-cache-0 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0d05c387-72ba-4d4d-90d0-b6293a09ed76 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=b4ad89e7-96a8-4753-8fdb-2d5ce5cfa75f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"87b49f8a-01f0-4e50-bf1f-bf78cd70ef4e","username":"system:serviceaccount:kube-system:statefulset-controller"} v=2 2026-06-29T22:19:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:statefulset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=loki-ingester-0 namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/loki-ingester-0 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ac36b1f8-90e5-4f05-964c-d61de10e2fb0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=b4ad89e7-96a8-4753-8fdb-2d5ce5cfa75f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"87b49f8a-01f0-4e50-bf1f-bf78cd70ef4e","username":"system:serviceaccount:kube-system:statefulset-controller"} v=2 2026-06-29T22:19:42Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=bootstrap-tenant-namespace-queue uid=51033b11-5e90-4f07-b386-8bbee0e09fbe v=2 2026-06-29T22:19:42Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=bootstrap-tenant-namespace-queue type=ClusterPolicy v=2 2026-06-29T22:19:48Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:19:48 http: TLS handshake error from 10.129.0.2:49686: EOF logger=webhooks/server v=0 2026-06-29T22:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712860 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712860 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b0f25478-9914-444b-af9d-20b84edbf79e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1dfbd7dd-0d04-4450-8975-ed65744dcbc0"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T22:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712860 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712860 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=57d9064e-ed4d-4dc4-8b95-8b5bdd4eeeed user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1dfbd7dd-0d04-4450-8975-ed65744dcbc0"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T22:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712860-76m8q namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712860-76m8q resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ab32d1f9-55cb-4d68-92ad-773a65dcc82d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4bef9aa1-3f90-40fd-8250-b788ab722565"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712860-t2dft namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712860-t2dft resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=70e9b491-9459-46b7-ad30-54711032615c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4bef9aa1-3f90-40fd-8250-b788ab722565"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:20:20Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=loki-minio-post-job namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Job/loki-minio-post-job resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=89a2efff-aca7-442c-8dec-48cb911c3ca6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:20:20Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=loki-minio-post-job-vmp28 namespace=product-kubearchive-logging operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive-logging/Pod/loki-minio-post-job-vmp28 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d252ee3d-080b-4ef9-8421-1f6f16296ae6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4bef9aa1-3f90-40fd-8250-b788ab722565"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:20:25Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=tekton-chains-signing-secret namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Job/tekton-chains-signing-secret resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=e8e6f4b2-b7b5-4553-9fe4-c04b68d881ee user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:20:25Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-chains-signing-secret-x2d9m namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-chains-signing-secret-x2d9m resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=01007ccf-b309-4e50-8174-1f7c6fd6ffb8 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4bef9aa1-3f90-40fd-8250-b788ab722565"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:23:09Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=tekton-results-watcher namespace=tekton-results operation=CREATE policy=restrict-docker-io-images resource=tekton-results/Deployment/tekton-results-watcher resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=f22a5ff3-1d2a-4f60-b125-0d25251ed698 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=798af983-096e-4453-b2fa-9fc83b4e7c72"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T22:23:09Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-results-watcher-55667bb668-sdp2j namespace=tekton-results operation=CREATE policy=restrict-docker-io-images resource=tekton-results/Pod/tekton-results-watcher-55667bb668-sdp2j resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=eae0da2b-7768-4b94-a072-52fd1eccee33 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8c90360d-0767-497f-9234-2cce34f8eedf"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T22:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712865 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712865 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=634a1eec-7f94-4528-878e-abc9c8c6d077 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1dfbd7dd-0d04-4450-8975-ed65744dcbc0"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T22:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712865-qdn25 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712865-qdn25 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6cf5ab94-9032-43a6-83c4-613787f2401b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4bef9aa1-3f90-40fd-8250-b788ab722565"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712870 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712870 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=71442cae-d817-4e92-801c-53c65b8abdd5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1dfbd7dd-0d04-4450-8975-ed65744dcbc0"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T22:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712870 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712870 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=3aa81635-76f2-42a1-9fb4-09a71d1cb9aa user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1dfbd7dd-0d04-4450-8975-ed65744dcbc0"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T22:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712870-4bkw2 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712870-4bkw2 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=da8f2ce5-67a5-4ef8-a3c0-dca8a12c7fdf user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4bef9aa1-3f90-40fd-8250-b788ab722565"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712870-f76k7 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712870-f76k7 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=016047a3-2387-4079-b9f6-bb550fb686b3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4bef9aa1-3f90-40fd-8250-b788ab722565"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:32:43Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:32:43 http: TLS handshake error from 10.130.0.2:50854: EOF logger=webhooks/server v=0 2026-06-29T22:32:43Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:32:43 http: TLS handshake error from 10.128.0.2:37680: EOF logger=webhooks/server v=0 2026-06-29T22:32:43Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:32:43 http: TLS handshake error from 10.129.0.2:56638: EOF logger=webhooks/server v=0 2026-06-29T22:33:31Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:33:31 http: TLS handshake error from 10.129.0.2:40202: EOF logger=webhooks/server v=0 2026-06-29T22:33:42Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="apps/v1, Kind=StatefulSet" gvr="apps/v1, Resource=statefulsets" kind=StatefulSet logger=webhooks/resource/validate name=affinity-assistant-3625d6287f namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/StatefulSet/affinity-assistant-3625d6287f resource.gvk="apps/v1, Kind=StatefulSet" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b635448f-51d2-4a7a-83fe-eee941ec3a83 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=951c1bd3-78b7-4312-83a2-0d23f7a1a7ec"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["0ce90150-212e-49ec-8e02-48515970a3dd"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:33:42Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:statefulset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=affinity-assistant-3625d6287f-0 namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/affinity-assistant-3625d6287f-0 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8f8de0ae-1872-447c-aee9-e3e98d214ee5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=b4ad89e7-96a8-4753-8fdb-2d5ce5cfa75f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"87b49f8a-01f0-4e50-bf1f-bf78cd70ef4e","username":"system:serviceaccount:kube-system:statefulset-controller"} v=2 2026-06-29T22:33:42Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-eqavofstwy-init-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/buildah-demo-eqavofstwy-init-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=96db4693-5fb2-44ee-9f64-3bbfacc440a6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:33:45Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-7tfm5 namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-7tfm5 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=74590ce2-9061-460a-be94-fac164d18673 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8c90360d-0767-497f-9234-2cce34f8eedf"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T22:34:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-eqavofstwy-clone-repository-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/buildah-demo-eqavofstwy-clone-repository-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=7bf8b7d3-7ff1-48c3-a813-1a287154e5ec user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=951c1bd3-78b7-4312-83a2-0d23f7a1a7ec"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["0ce90150-212e-49ec-8e02-48515970a3dd"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:34:28Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=buildah-demo-eqavofstwy-prefetch-dependencies-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=c22585a8-a430-4e6c-abb7-2f1d5ece4c4b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=951c1bd3-78b7-4312-83a2-0d23f7a1a7ec"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["0ce90150-212e-49ec-8e02-48515970a3dd"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:34:28Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=buildah-demo-eqavofstwy-prefetch-dependencies-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=0b109375-58ee-42e5-a4b2-57a1970a15d4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=951c1bd3-78b7-4312-83a2-0d23f7a1a7ec"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["0ce90150-212e-49ec-8e02-48515970a3dd"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:34:28Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-eqavofstwy-prefetch-dependencies-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/buildah-demo-eqavofstwy-prefetch-dependencies-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=7d8d25eb-27b7-454b-898b-ef678e23f857 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=951c1bd3-78b7-4312-83a2-0d23f7a1a7ec"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["0ce90150-212e-49ec-8e02-48515970a3dd"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:34:31Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-9nc6k namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-9nc6k resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9cea5445-5c00-416d-9c71-c470397f8c91 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8c90360d-0767-497f-9234-2cce34f8eedf"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T22:34:44Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-eqavofstwy-build-container-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/buildah-demo-eqavofstwy-build-container-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=29ea6c06-3837-4652-9e26-919a2ad67174 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=951c1bd3-78b7-4312-83a2-0d23f7a1a7ec"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["0ce90150-212e-49ec-8e02-48515970a3dd"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712875 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712875 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2cdd62d0-43d6-4666-b87b-cfb252abd47f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1dfbd7dd-0d04-4450-8975-ed65744dcbc0"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T22:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712875-vzkmg namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712875-vzkmg resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d8ba1226-33c7-4fc3-a263-5b64e2599fe8 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4bef9aa1-3f90-40fd-8250-b788ab722565"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:35:31Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-s7mn6 namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-s7mn6 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=bda344d4-0578-4497-91a3-0e8f44ea2a16 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8c90360d-0767-497f-9234-2cce34f8eedf"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T22:36:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-eqavofstwy-build-image-index-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/buildah-demo-eqavofstwy-build-image-index-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=fb73196a-c1cb-4772-badb-ebf1c195f62b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:37:23Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:37:23 http: TLS handshake error from 10.128.0.2:37354: EOF logger=webhooks/server v=0 2026-06-29T22:37:23Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-eqavofstwy-apply-tags-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/buildah-demo-eqavofstwy-apply-tags-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f3b6fcae-1ccf-4981-8a13-d092b0d6233e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:37:23Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-eqavofstwy-push-dockerfile-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/buildah-demo-eqavofstwy-push-dockerfile-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=3b656d95-4d30-414f-b152-5e0c88aeb078 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:37:55Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-9a5aa80997b34d2291e00836106a4e2a-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=4a4456cf-d870-44d5-92da-527d0fd3cf9c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:37:55Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-9a5aa80997b34d2291e00836106a4e2a-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=e8b8958d-66e2-4753-b120-62cd200bdeb5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:37:55Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-9a5aa80997b34d2291e00836106a4e2a-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/verify-enterprise-contract-9a5aa80997b34d2291e00836106a4e2a-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=3423afd3-7981-4daa-8ce8-c06f2459ddf9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:38:16Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-939d4234ffbadc69e3c583bab37906ab-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=3673c052-b8ff-4359-9708-81e37f7bff04 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:38:16Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-939d4234ffbadc69e3c583bab37906ab-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=e3cb7908-a21e-44ac-8d08-2f09f9a7da3f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:38:16Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-939d4234ffbadc69e3c583bab37906ab-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/verify-enterprise-contract-939d4234ffbadc69e3c583bab37906ab-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=91d77183-4ed9-4541-a065-77faa9839fcd user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:38:35Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-86e0bdcbcc40b77f2518350629b09aa6-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=6b85c409-83d2-4739-b514-19c1a5e631d6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=951c1bd3-78b7-4312-83a2-0d23f7a1a7ec"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["0ce90150-212e-49ec-8e02-48515970a3dd"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:38:35Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-86e0bdcbcc40b77f2518350629b09aa6-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=18c34502-7195-43f1-9ed8-89d15d1fc52b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=951c1bd3-78b7-4312-83a2-0d23f7a1a7ec"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["0ce90150-212e-49ec-8e02-48515970a3dd"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:38:35Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-86e0bdcbcc40b77f2518350629b09aa6-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/verify-enterprise-contract-86e0bdcbcc40b77f2518350629b09aa6-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e285a66a-6671-430d-b791-0dfb977e7ccb user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=951c1bd3-78b7-4312-83a2-0d23f7a1a7ec"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["0ce90150-212e-49ec-8e02-48515970a3dd"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:38:50Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-b22459da8f6fc87cf0b7f0b041433bbf-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=9b72bfee-85af-42e2-a1ce-d89eaff310e3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:38:50Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-b22459da8f6fc87cf0b7f0b041433bbf-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=57bbe570-81ff-4fad-82dc-24ff1cc5321f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:38:50Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-b22459da8f6fc87cf0b7f0b041433bbf-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/verify-enterprise-contract-b22459da8f6fc87cf0b7f0b041433bbf-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5e62ddc8-1ace-4142-842a-c37e4e96059e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:39:02Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-503b21fdcf32b6aec70c17ad0b20f4d6-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=870114a7-ded0-41ea-b3ab-7ac1986188e6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:39:02Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-503b21fdcf32b6aec70c17ad0b20f4d6-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=c03158cf-6661-47d1-b0fa-a00e0a6bbd27 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:39:02Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-503b21fdcf32b6aec70c17ad0b20f4d6-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/verify-enterprise-contract-503b21fdcf32b6aec70c17ad0b20f4d6-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2c57815d-5e05-43ae-9782-4edca6c45508 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:39:16Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-159cc5bc7a3a4686a14e2a7a99f0302f-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=6a23ae96-efd2-4479-807b-baf9faa67923 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:39:16Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-159cc5bc7a3a4686a14e2a7a99f0302f-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=3ac45aaa-7a67-46c4-b619-666d828ad6e1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:39:17Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-159cc5bc7a3a4686a14e2a7a99f0302f-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/verify-enterprise-contract-159cc5bc7a3a4686a14e2a7a99f0302f-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=3c169d5e-3c5f-407a-a5fe-01f351fc7097 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:39:35Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-53eb25498e9379569ca2b7ddb1250704-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=be116f4e-571e-49c7-82d3-1b956895e694 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:39:36Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-53eb25498e9379569ca2b7ddb1250704-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=3f6639b9-9c70-4f6a-a864-654f7891fecc user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:39:36Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-53eb25498e9379569ca2b7ddb1250704-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/verify-enterprise-contract-53eb25498e9379569ca2b7ddb1250704-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d22b6ebd-6302-440c-a1a5-ab2c83106b98 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712880 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712880 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b302adbf-7ce6-4d06-90e4-c2ad1ee0a5c8 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1dfbd7dd-0d04-4450-8975-ed65744dcbc0"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T22:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712880 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712880 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1defd5be-b356-4476-bfa7-f170f89072f7 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1dfbd7dd-0d04-4450-8975-ed65744dcbc0"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T22:40:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:00 http: TLS handshake error from 10.128.0.2:52182: EOF logger=webhooks/server v=0 2026-06-29T22:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712880-7cvzk namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712880-7cvzk resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6ea03f03-e7fa-48e3-9fbd-c0dc1196092e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4bef9aa1-3f90-40fd-8250-b788ab722565"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712880-qhbvb namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712880-qhbvb resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=eae51772-ea5e-4ce1-b40f-86a3d04ee253 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4bef9aa1-3f90-40fd-8250-b788ab722565"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:40:09Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-6a168efb6b0692ab5eb45065c650176d-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=5e66a9f6-7812-4b2e-840c-560dc35addcd user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=951c1bd3-78b7-4312-83a2-0d23f7a1a7ec"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["0ce90150-212e-49ec-8e02-48515970a3dd"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:40:09Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-6a168efb6b0692ab5eb45065c650176d-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=c8dcd2d7-c287-4f25-84f2-663f7d6260a4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=951c1bd3-78b7-4312-83a2-0d23f7a1a7ec"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["0ce90150-212e-49ec-8e02-48515970a3dd"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:40:09Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-6a168efb6b0692ab5eb45065c650176d-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/verify-enterprise-contract-6a168efb6b0692ab5eb45065c650176d-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=553fa460-1e0c-41ff-8cd9-ccd78069eb87 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=951c1bd3-78b7-4312-83a2-0d23f7a1a7ec"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["0ce90150-212e-49ec-8e02-48515970a3dd"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:40:26Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-ef1bacac16d0f23c8269f99263385b25-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=4dd91ee7-245c-46cb-9655-712a81b28033 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:40:26Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-ef1bacac16d0f23c8269f99263385b25-pod namespace=chains-e2e-ktby operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=b4a4de29-a169-47df-b3ad-1fbf9a8d88e4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:40:26Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-ef1bacac16d0f23c8269f99263385b25-pod namespace=chains-e2e-ktby operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-ktby/Pod/verify-enterprise-contract-ef1bacac16d0f23c8269f99263385b25-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=fadacea8-48d6-4b03-957e-29c71ae1b1f5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cd9bc693-2a8d-43a7-af21-51d86757dba9"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T22:40:41Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:41 http: TLS handshake error from 10.129.0.2:51322: EOF logger=webhooks/server v=0 2026-06-29T22:40:41Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:41 http: TLS handshake error from 10.129.0.2:43566: EOF logger=webhooks/server v=0 2026-06-29T22:40:41Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:41 http: TLS handshake error from 10.129.0.2:43554: EOF logger=webhooks/server v=0 2026-06-29T22:40:41Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:41 http: TLS handshake error from 10.129.0.2:43568: EOF logger=webhooks/server v=0 2026-06-29T22:40:41Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:41 http: TLS handshake error from 10.130.0.2:41408: EOF logger=webhooks/server v=0 2026-06-29T22:40:45Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:45 http: TLS handshake error from 10.128.0.2:38704: EOF logger=webhooks/server v=0 2026-06-29T22:40:45Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:45 http: TLS handshake error from 10.130.0.2:52032: EOF logger=webhooks/server v=0 2026-06-29T22:40:45Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:45 http: TLS handshake error from 10.128.0.2:38718: EOF logger=webhooks/server v=0 2026-06-29T22:40:45Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:45 http: TLS handshake error from 10.129.0.2:43586: EOF logger=webhooks/server v=0 2026-06-29T22:40:46Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:46 http: TLS handshake error from 10.128.0.2:38734: EOF logger=webhooks/server v=0 2026-06-29T22:40:47Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:47 http: TLS handshake error from 10.128.0.2:38750: EOF logger=webhooks/server v=0 2026-06-29T22:40:47Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:47 http: TLS handshake error from 10.128.0.2:38766: EOF logger=webhooks/server v=0 2026-06-29T22:40:47Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:47 http: TLS handshake error from 10.130.0.2:52042: EOF logger=webhooks/server v=0 2026-06-29T22:40:48Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:48 http: TLS handshake error from 10.130.0.2:52046: EOF logger=webhooks/server v=0 2026-06-29T22:40:49Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:49 http: TLS handshake error from 10.128.0.2:38770: EOF logger=webhooks/server v=0 2026-06-29T22:40:49Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:40:49 http: TLS handshake error from 10.129.0.2:43604: EOF logger=webhooks/server v=0 2026-06-29T22:44:23Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-brbnw namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-brbnw resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=7357f60f-5ddf-450f-8a9d-f57beedbd8ac user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-06-29T22:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712885 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712885 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=809472ff-f2cb-4ce6-b501-0f4958287caf user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1dfbd7dd-0d04-4450-8975-ed65744dcbc0"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T22:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712885-4xjzp namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712885-4xjzp resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f28eb979-87b8-41e6-b65d-c8410a427d12 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4bef9aa1-3f90-40fd-8250-b788ab722565"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712890 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712890 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8955e39a-f127-49ad-a588-bd755341cf4e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T22:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712890 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712890 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9f5006e6-3f1c-4333-af48-35f0864718eb user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T22:50:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 22:50:00 http: TLS handshake error from 10.130.0.2:40138: EOF logger=webhooks/server v=0 2026-06-29T22:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712890-44lds namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712890-44lds resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=761f0015-0b2c-4b70-b79d-5c49d7ef73e1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712890-xn82m namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712890-xn82m resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a1bbf369-4798-47b1-a2c2-34c75790ec97 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T22:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712895 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712895 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=bc51ed2b-dff5-4694-9374-adb39f069a83 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T22:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712895-9q7gl namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712895-9q7gl resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4af4bac3-bd42-405c-9ff3-d864028b17ac user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712900 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712900 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=95a78ff6-4eb9-484c-b456-4bde1969b3b3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=namespace-claim-cleaner-29712900 namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Job/namespace-claim-cleaner-29712900 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=dcbb47a2-244f-4259-9d49-7ae0c1f61fb9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712900 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712900 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b2c902c7-9337-44c1-8ca9-7369efa9b09f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 23:00:00 http: TLS handshake error from 10.130.0.2:59438: EOF logger=webhooks/server v=0 2026-06-29T23:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712900-x4cs6 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712900-x4cs6 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=11e31a1b-86fa-4598-8d65-528112e3029f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 23:00:00 http: TLS handshake error from 10.128.0.2:48088: EOF logger=webhooks/server v=0 2026-06-29T23:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=namespace-claim-cleaner-29712900-qpmhg namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Pod/namespace-claim-cleaner-29712900-qpmhg resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=de6b7c71-0362-42bc-8744-ebcbad0dbb9e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712900-4dclt namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712900-4dclt resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=aa700e96-03df-414e-b753-af506ec9724c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712905 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712905 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=893e9c88-3d01-4bae-9210-ac6c377a2387 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712905-4cmz8 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712905-4cmz8 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f33634ba-549d-4ab9-92fa-6f2652d8cbcc user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712910 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712910 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1f45b7e8-7d2e-4805-9421-04c71fff45fb user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712910 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712910 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=51ee69fb-5057-4f26-9f14-f0043577aeac user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712910-nkff2 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712910-nkff2 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d9eac273-699b-4f90-8882-ef8f12819874 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712910-22w42 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712910-22w42 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=46e60795-2cd5-4fac-ba77-fde127b500a1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:13:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=oauth-secret-generator namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Job/oauth-secret-generator resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=3bc0de83-76c7-4baa-b370-3daa11866d9d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a411ab6f-15ef-40a0-ae11-3a1ad2ca7117"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["8471998b-a1ee-48d5-9b28-2c234b07faaf"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"d5c6f63e-8b81-44da-8d88-4dba33cc9005","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T23:13:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=oauth-secret-generator-tnp9p namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/oauth-secret-generator-tnp9p resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c46d403f-1f4e-4b41-9b59-c5bf37c32991 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:13:54Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=image-rbac-proxy-648676dd6d-cjgnk namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/image-rbac-proxy-648676dd6d-cjgnk resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d07572af-6e98-4749-967c-cfde7cb9f358 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=fbb30f8a-2eca-45a1-8303-66c9a6a4bc53"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T23:13:54Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=dex-7f7d87cb9f-vfqh9 namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/dex-7f7d87cb9f-vfqh9 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ade1d59a-eb09-4c26-8b31-8b0ad3e91169 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=fbb30f8a-2eca-45a1-8303-66c9a6a4bc53"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"fe328132-883e-4723-936f-0aae70295ae6","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T23:14:23Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-lzh2p namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-lzh2p resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4e7256a7-233b-47e3-beca-e917faa5b3f8 user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-06-29T23:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712915 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712915 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ff26b35f-a239-4ce3-b6b5-956e5ced11ce user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712915-7k5vf namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712915-7k5vf resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2c08ab64-93f6-4120-be34-eac351786ee6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:15:36Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 23:15:36 http: TLS handshake error from 10.130.0.2:47944: EOF logger=webhooks/server v=0 2026-06-29T23:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712920 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712920 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2bbb1abd-2964-4ca4-9326-09063ba284bb user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712920 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712920 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ac6ee5b9-907d-40b1-9c03-e8687b6f6e71 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:20:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 23:20:00 http: TLS handshake error from 10.129.0.2:53970: EOF logger=webhooks/server v=0 2026-06-29T23:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712920-vxc8r namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712920-vxc8r resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6f654e42-9c85-455b-ae8f-90241acc23fa user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712920-h92b4 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712920-h92b4 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9b546f38-2d3d-40c6-9ab4-69565e4828d3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712925 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712925 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=276ab864-6498-4cd8-aae5-6df99b9f6c94 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712925-wlv9b namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712925-wlv9b resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=db378e66-209d-4eae-85cb-309a3eb5864d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712930 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712930 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e520b5f8-0cb5-4258-ab80-0e56d5f0a673 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712930 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712930 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8d9dcef5-4898-45d1-9ed1-257c49de654a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712930-fqvj7 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712930-fqvj7 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c6c285e1-ec72-4c9a-8585-c14e203a673a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712930-5hxf8 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712930-5hxf8 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1bad96b2-f776-4ef9-9015-ace4a2b5bb94 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712935 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712935 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4e93bb74-228d-4d51-8d70-6dce5dd0c5ae user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=45c55530-0984-48b5-b92d-23ca6e46b082"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712935-wngvm namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712935-wngvm resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d1aef1cd-7507-4920-84dc-6bc42222facd user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=69d1fab8-0c54-40ab-8461-8896d29a7ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712940 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712940 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0fa034a0-2bcf-4106-a8ee-29dd81e8d013 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712940 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712940 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4acbbff2-a415-407f-aabf-c538bbe01d96 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:40:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 23:40:00 http: TLS handshake error from 10.128.0.2:42014: EOF logger=webhooks/server v=0 2026-06-29T23:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712940-s7s6s namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712940-s7s6s resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d2489b4f-7b8a-44d4-a0bb-326ac52a839a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712940-wsldz namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712940-wsldz resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c317a77c-c425-4032-acb5-83e6e1484ddc user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:44:23Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-j28qc namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-j28qc resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f33d2368-5c09-4d64-a497-8a8981cc9163 user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-06-29T23:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712945 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712945 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d1ddbe24-5bd4-4774-8ae5-c3840c53c42f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712945-9btxg namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712945-9btxg resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=82d552a4-7374-4094-af86-72f1c644240b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712950 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712950 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0afb5056-d809-43d7-9fd9-8f6a69ca03fb user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712950 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712950 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=141fdd20-4a00-4918-8e78-655021eff95c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:50:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 23:50:00 http: TLS handshake error from 10.128.0.2:60584: EOF logger=webhooks/server v=0 2026-06-29T23:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712950-xg452 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712950-xg452 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ec5359f3-5217-454b-a5bc-cc5113e11517 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712950-gn6bw namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712950-gn6bw resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6af0d22a-2b81-455a-8439-c403d90f27ad user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T23:51:50Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 23:51:50 http: TLS handshake error from 10.128.0.2:40178: EOF logger=webhooks/server v=0 2026-06-29T23:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712955 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712955 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=296ddcbc-11f9-405c-aae8-b87e5b140044 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T23:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712955-lwkj8 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712955-lwkj8 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=fd512c59-1964-481b-a3ef-f0d18004143a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=image-controller-image-pruner-cronjob-29712960 namespace=image-controller operation=CREATE policy=restrict-docker-io-images resource=image-controller/Job/image-controller-image-pruner-cronjob-29712960 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5bee2daa-616c-4185-b09e-74963d8e2a59 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712960 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712960 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0b772e57-5515-4382-b1a4-7c152b1fdba9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=image-pruner-29712960 namespace=openshift-image-registry operation=CREATE policy=restrict-docker-io-images resource=openshift-image-registry/Job/image-pruner-29712960 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f4225943-9880-4b6d-9915-c1ff6bc44e12 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=integration-service-snapshot-garbage-collector-29712960 namespace=integration-service operation=CREATE policy=restrict-docker-io-images resource=integration-service/Job/integration-service-snapshot-garbage-collector-29712960 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=604f6868-c4f1-4a66-ac5c-27d0151fa178 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=create-dependencyupdatecheck-29712960 namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Job/create-dependencyupdatecheck-29712960 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=7f9ea52d-8e5a-4c41-a1a8-8cdd8f8a89f1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712960 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712960 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b25e8f6d-75ec-4868-b0c4-a8da1515c6be user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=namespace-claim-cleaner-29712960 namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Job/namespace-claim-cleaner-29712960 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=49f1f5cb-5f55-4ffb-9fb0-c1f419592c82 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5170dd17-cca6-4682-94e7-8a624f5d25a5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"6a9663fe-80ec-447f-af0a-8546362f7a32","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=image-controller-image-pruner-cronjob-29712960-xjhdh namespace=image-controller operation=CREATE policy=restrict-docker-io-images resource=image-controller/Pod/image-controller-image-pruner-cronjob-29712960-xjhdh resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=03fe86ad-47cf-4c26-8d20-ff9c17d40285 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-30T00:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/30 00:00:00 http: TLS handshake error from 10.128.0.2:42502: EOF logger=webhooks/server v=0 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=create-dependencyupdatecheck-29712960-tsjns namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Pod/create-dependencyupdatecheck-29712960-tsjns resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e0c929bb-b5ee-42f4-a14f-b957a559b637 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=image-pruner-29712960-c9m74 namespace=openshift-image-registry operation=CREATE policy=restrict-docker-io-images resource=openshift-image-registry/Pod/image-pruner-29712960-c9m74 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8190b013-312b-4404-b256-bbdca37181fe user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-30T00:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/30 00:00:00 http: TLS handshake error from 10.130.0.2:37510: EOF logger=webhooks/server v=0 2026-06-30T00:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/30 00:00:00 http: TLS handshake error from 10.130.0.2:37514: EOF logger=webhooks/server v=0 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712960-bzr68 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712960-bzr68 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b1b6acef-9b3e-4e3d-8b5b-a7c90932cf24 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712960-9dlrj namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712960-9dlrj resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b8e21c9b-1305-4339-a3cf-e0128805b028 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=integration-service-snapshot-garbage-collector-29712960-ksw8v namespace=integration-service operation=CREATE policy=restrict-docker-io-images resource=integration-service/Pod/integration-service-snapshot-garbage-collector-29712960-ksw8v resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=798eb519-6926-47c8-8b79-a7ef753794d6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-30T00:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=namespace-claim-cleaner-29712960-kt8jn namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Pod/namespace-claim-cleaner-29712960-kt8jn resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=889d8d0e-9507-4151-b172-1ff97ea65be1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfaece7a-66fd-4fee-b752-c6647af42265"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"b2201b18-72af-4317-9819-2475210aa0c9","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-30T00:00:17Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=renovate-06300000-c6b03658-build-pod namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Pod/renovate-06300000-c6b03658-build-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=675ff53e-c2d0-410c-b4ce-f4823190e88f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=23196ec2-3ec6-4532-8ea6-aa22783bd4fd"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-30T00:00:17Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=renovate-06300000-c089aa0f-build-pod namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Pod/renovate-06300000-c089aa0f-build-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=db2a23e7-b7f6-4908-8dbf-eb9e76b4e099 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=23196ec2-3ec6-4532-8ea6-aa22783bd4fd"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["35d2e5c4-a885-4e89-bba1-d756376b53ae"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"b70d8688-5de6-4249-a024-d413a6bd28cd","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2