2026-07-02T02:16:33Z TRC kyverno/pkg/version/version.go:49 > version hash=--- logger=setup/version v=2 version=1.25.8 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > add_dir_header=false logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > admissionReports=false logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > allowInsecureRegistry=false logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > alsologtostderr=false logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > autoDeleteWebhooks=false logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > autoUpdateWebhooks=true logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > backgroundServiceAccountName=system:serviceaccount:konflux-kyverno:kyverno-background-controller logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > caSecretName=konflux-kyverno-svc.konflux-kyverno.svc.kyverno-tls-ca logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > cleanupServerPort=9443 logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > clientRateLimitBurst=200 logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > clientRateLimitQPS=100 logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > controllerRuntimeMetricsAddress=:8080 logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > crdWatcher=false logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > disableLogColor=false logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > disableMetrics=false logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > dumpPatches= logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > dumpPayload=false logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > enableConfigMapCaching=true logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > enableDeferredLoading= logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > enablePolicyException=false logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > enableReporting= logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > enableTracing=false logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > enableTuf=false logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > eventsRateLimitBurst=2000 logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > eventsRateLimitQPS=1000 logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > exceptionNamespace= logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > forceFailurePolicyIgnore= logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > generateMutatingAdmissionPolicy= logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > generateValidatingAdmissionPolicy= logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > imagePullSecrets= logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheEnabled=true logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheMaxSize=1000 logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheTTLDuration=1h0m0s logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > kubeconfig= logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > leaderElectionRetryPeriod=26s logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > log_backtrace_at=:0 logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > log_dir= logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > log_file= logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > log_file_max_size=1800 logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag loggingFormat=text v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag loggingtsFormat=default v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag logtostderr=true v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAPICallResponseLength=2000000 v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAdmissionReports=1000 v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAuditCapacity=1000 v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAuditWorkers=8 v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxQueuedEvents=1000 v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag metricsPort=8000 v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag omitEvents=PolicyApplied,PolicySkipped v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag one_output=false v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag otelCollector=opentelemetrycollector.kyverno.svc.cluster.local v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag otelConfig=prometheus v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profile=false v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profileAddress= v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profilePort=6060 v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag protectManagedResources= v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag registryCredentialHelpers=default,google,amazon,azure,github v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag renewBefore=360h0m0s v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag reportsServiceAccountName= v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag resyncPeriod=15m0s v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag serverIP= v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag servicePort=443 v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag skip_headers=false v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag skip_log_headers=false v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag stderrthreshold=2 v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tlsSecretName=konflux-kyverno-svc.konflux-kyverno.svc.kyverno-tls-pair v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingAddress= v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingCreds= v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingPort=4317 v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag transportCreds= v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufMirror=https://tuf-repo-cdn.sigstore.dev v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufRoot= v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufRootRaw= v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 vmodule= 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookRegistrationTimeout=2m0s 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookServerPort=9443 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookTimeout=10 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/maxprocs.go:12 > setup maxprocs... logger=setup/maxprocs v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/signal.go:16 > setup signals... logger=setup/signals v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/kube-client qps=100 v=2 2026-07-02T02:16:33Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=ClientsAllowCBOR logger=klog v=1 2026-07-02T02:16:33Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=ClientsPreferCBOR logger=klog v=1 2026-07-02T02:16:33Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=InformerResourceVersion logger=klog v=1 2026-07-02T02:16:33Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=true feature=InOrderInformers logger=klog v=1 2026-07-02T02:16:33Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=WatchListClient logger=klog v=1 2026-07-02T02:16:33Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/metrics.go:18 > setup metrics... collector=opentelemetrycollector.kyverno.svc.cluster.local creds= logger=setup/metrics otel=prometheus port=8000 v=2 2026-07-02T02:16:33Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:417 > defaultRegistry configured defaultRegistry=docker.io logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:433 > enableDefaultRegistryMutation configured enableDefaultRegistryMutation=true logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:442 > excludedGroups configured excludeGroups=["system:nodes"] includeGroups=[] logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:447 > excludeUsernames not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:455 > excludeRoles not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:463 > excludeClusterRoles not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:479 > generateSuccessEvents configured generateSuccessEvents=false logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:493 > webhooks configured logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 webhooks="{\"namespaceSelector\":{\"matchExpressions\":[{\"key\":\"kubernetes.io/metadata.name\",\"operator\":\"NotIn\",\"values\":[\"kube-system\"]},{\"key\":\"kubernetes.io/metadata.name\",\"operator\":\"NotIn\",\"values\":[\"konflux-kyverno\"]}],\"matchLabels\":null}}" 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:507 > webhookAnnotations configured logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 webhookAnnotations="{\"admissions.enforcer/disabled\":\"true\"}" 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:513 > webhookLabels not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:527 > matchConditions not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:548 > enableDefaultRegistryMutation configured enableDefaultRegistryMutation=true logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-02T02:16:33Z TRC kyverno/pkg/config/config.go:563 > maxContextSize not set, using default default=2097152 logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-02T02:16:33Z TRC kyverno/cmd/internal/registry.go:18 > setup registry client... insecure=false logger=setup/registry-client secrets= v=2 2026-07-02T02:16:33Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/imageverifycache.go:10 > setup image verify cache... enabled=true logger=setup/image-verify-cache maxsize=1000 ttl=1h0m0s v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/kube-client qps=100 v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/client.go:60 > create kyverno client... burst=200 kubeconfig= logger=setup/kyverno-client qps=100 v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/client.go:68 > create dynamic client... burst=200 kubeconfig= logger=setup/dynamic-client qps=100 v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/client.go:84 > create apiserver client... burst=200 kubeconfig= logger=setup/apiserver-client qps=100 v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/client.go:76 > create metadata client... burst=200 kubeconfig= logger=setup/metadata-client qps=100 v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/client.go:92 > create the kyverno dynamic client... burst=200 kubeconfig= logger=setup/d-client qps=100 v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/client.go:100 > create the events client... burst=200 kubeconfig= logger=setup/events-client qps=100 v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/events-client/kube-client qps=100 v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/reporting.go:13 > setting up reporting... enableReporting= generate=false imageVerify=false logger=setup/setup-reporting mutate=false mutateExisiting=false v=2 validate=false 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Deployment v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/engine.go:65 > setup exception selector... enablePolicyException=false exceptionNamespace= logger=setup/exception-selector v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/engine.go:94 > setup config map resolver... enableConfigMapCaching=true logger=setup/configmap-resolver v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/engine.go:46 > setup engine... logger=setup/engine v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Deployment v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2alpha1.GlobalContextEntry v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Policy v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterPolicy v=2 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/metrics/server/server.go:208 > Starting metrics server logger=controller-runtime/metrics v=0 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/metrics/server/server.go:247 > Serving metrics server bindAddress=:8080 logger=controller-runtime/metrics secure=false v=0 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy source="kind source: *v1alpha1.MutatingPolicy" v=0 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy source="kind source: *v1alpha1.ValidatingPolicy" v=0 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy source="kind source: *v1alpha1.ImageValidatingPolicy" v=0 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.PolicyException v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Namespace v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterRoleBinding v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.RoleBinding v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2.UpdateRequest v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.GeneratingPolicy v=2 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/leaderelection/leaderelection.go:257 > attempting to acquire leader lease konflux-kyverno/kyverno... logger=klog v=0 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup name=kyverno-events v=2 workers=3 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup name=global-context v=2 workers=1 2026-07-02T02:16:34Z TRC kyverno/pkg/event/controller.go:106 > start logger=EventGenerator v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/controllers name=policycache-controller v=2 workers=3 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.MutatingPolicy v=2 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/leaderelection/leaderelection.go:271 > successfully acquired lease konflux-kyverno/kyverno logger=klog v=0 2026-07-02T02:16:34Z TRC kyverno/pkg/leaderelection/leaderelection.go:83 > started leading id=kyverno-admission-controller-5cbb799dc8-7zh6d logger=setup/leader-election v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.GeneratingPolicy v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.MutatingPolicy v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Policy v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Lease v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingWebhookConfiguration v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.PolicyException v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingAdmissionPolicy v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterPolicy v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingAdmissionPolicyBinding v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.MutatingWebhookConfiguration v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ImageValidatingPolicy v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterRole v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ValidatingPolicy v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ValidatingPolicy v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ImageValidatingPolicy v=2 2026-07-02T02:16:34Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2.PolicyException v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=global-context-webhook-controller v=2 workers=1 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=webhook-controller v=2 workers=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=status-controller v=2 workers=3 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=admissionpolicy-generator v=2 workers=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=certmanager-controller v=2 workers=1 2026-07-02T02:16:34Z TRC kyverno/pkg/utils/controller/run.go:58 > starting ... logger=admissionpolicy-generator v=2 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=celexception-webhook-controller v=2 workers=1 2026-07-02T02:16:34Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=exception-webhook-controller v=2 workers=1 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy v=0 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy v=0 worker count=1 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy v=0 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy v=0 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy v=0 worker count=1 2026-07-02T02:16:34Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy v=0 worker count=1 2026-07-02T02:20:14Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:20:14 http: TLS handshake error from 10.129.0.2:49506: EOF logger=webhooks/server v=0 2026-07-02T02:20:14Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:20:14 http: TLS handshake error from 10.128.0.2:49498: EOF logger=webhooks/server v=0 2026-07-02T02:20:14Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:20:14 http: TLS handshake error from 10.130.0.2:47114: EOF logger=webhooks/server v=0 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpconsole uid=d93af875-60d4-459d-9428-64deb9fc965f v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpconsole type=ClusterPolicy v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-olm uid=c3bcda65-044a-49dc-8865-cb2cfdfbaf05 v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-olm type=ClusterPolicy v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-samenamespace type=ClusterPolicy v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-samenamespace uid=e9c9f127-62df-42ec-8aeb-fa63b0418aa3 v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpmonitoring type=ClusterPolicy v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpingress type=ClusterPolicy v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpmonitoring uid=f041e9ab-d282-40ea-93ba-4240e7c19228 v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpingress uid=78fdf358-71f1-4212-a55b-326373393f39 v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=init-ns-kubearchiveconfig type=ClusterPolicy v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-rbcm type=ClusterPolicy v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=init-ns-kubearchiveconfig uid=e6b68460-b018-4270-b396-3e89a6ee51b8 v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-rbcm uid=d3555ffc-8c9f-4185-a3d2-1e6a5de94d8e v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=integration-init-ns-integration type=ClusterPolicy v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=integration-init-ns-integration uid=98ff2254-3380-4562-8e5b-0d5bbfc0fec9 v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-generate-konflux-viewer-access type=ClusterPolicy v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-generate-konflux-viewer-access uid=95e936d5-f030-4808-a3ed-7c8380737474 v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-validate-restrict-binding-sysauth-releng type=ClusterPolicy v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-validate-restrict-binding-sysauth-releng uid=eadcbe1e-790c-432b-a6dc-43c96895020e v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-validate-restrict-binding-system-authenticated uid=7e702b3f-eb7d-48aa-b6c2-8305eee23863 v=2 2026-07-02T02:20:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-validate-restrict-binding-system-authenticated type=ClusterPolicy v=2 2026-07-02T02:20:14Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"konflux-rbac-validate-restrict-binding-sysauth-releng\": the object has been modified; please apply your changes to the latest version and try again" konflux-rbac-validate-restrict-binding-sysauth-releng=status 2026-07-02T02:20:14Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"konflux-rbac-validate-restrict-binding-system-authenticated\": the object has been modified; please apply your changes to the latest version and try again" konflux-rbac-validate-restrict-binding-system-authenticated=status 2026-07-02T02:20:15Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=tekton-taskrun-resource-policy uid=b6608f46-b44c-4d42-a20a-63980e916ddf v=2 2026-07-02T02:20:15Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=tekton-taskrun-resource-policy type=ClusterPolicy v=2 2026-07-02T02:20:15Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=restrict-docker-io-images type=ClusterPolicy v=2 2026-07-02T02:20:15Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=restrict-docker-io-images uid=2ecbbee6-a42d-42de-9723-c4a43b13b7cc v=2 2026-07-02T02:20:15Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=restrict-binding-system-groups uid=83682f64-d5a6-4b4d-b582-bf8e0c9bd298 v=2 2026-07-02T02:20:15Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=restrict-binding-system-groups type=ClusterPolicy v=2 2026-07-02T02:20:15Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"restrict-docker-io-images\": the object has been modified; please apply your changes to the latest version and try again" restrict-docker-io-images=status 2026-07-02T02:20:19Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=bootstrap-tenant-namespace-queue uid=614d02fc-8f75-4f6d-bf4e-d415e0601b85 v=2 2026-07-02T02:20:19Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=bootstrap-tenant-namespace-queue type=ClusterPolicy v=2 2026-07-02T02:20:40Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=tempo-operator-controller namespace=tempo-operator operation=CREATE policy=restrict-docker-io-images resource=tempo-operator/Deployment/tempo-operator-controller resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6808ec55-d9df-4dac-84f1-a3fabb04506e user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-07-02T02:20:41Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tempo-operator-controller-76bcb9f9bd-m2rf5 namespace=tempo-operator operation=CREATE policy=restrict-docker-io-images resource=tempo-operator/Pod/tempo-operator-controller-76bcb9f9bd-m2rf5 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=abc3cb0b-5bc4-4b09-a414-4d142152af71 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2e1f46a7-267c-4b05-a05c-50a49b8dc820"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"80348bd6-9110-4c1b-84bf-fcec4fe51c05","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-02T02:20:44Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:20:44 http: TLS handshake error from 10.128.0.2:54684: EOF logger=webhooks/server v=0 2026-07-02T02:20:44Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:20:44 http: TLS handshake error from 10.129.0.2:56222: EOF logger=webhooks/server v=0 2026-07-02T02:20:45Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:20:45 http: TLS handshake error from 10.128.0.2:54700: EOF logger=webhooks/server v=0 2026-07-02T02:21:56Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=tekton-results-watcher namespace=tekton-results operation=CREATE policy=restrict-docker-io-images resource=tekton-results/Deployment/tekton-results-watcher resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=08aaf0de-7de9-4e1f-80ff-cc9614b292a9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=828b02c6-08a3-42d2-8aed-986411738386"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["c8283afb-8240-46f1-9b41-44ff58008bf2"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"e9cf1689-12a4-446a-bba4-3ff29e2c74bb","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-07-02T02:21:57Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-results-watcher-55667bb668-977qz namespace=tekton-results operation=CREATE policy=restrict-docker-io-images resource=tekton-results/Pod/tekton-results-watcher-55667bb668-977qz resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=721f68e4-5c9c-4497-b59d-1d9ca6744944 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2e1f46a7-267c-4b05-a05c-50a49b8dc820"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"80348bd6-9110-4c1b-84bf-fcec4fe51c05","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-02T02:21:58Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:21:58 http: TLS handshake error from 10.129.0.2:38730: EOF logger=webhooks/server v=0 2026-07-02T02:21:58Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:auth-delegator","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role","tempo-operator.v0.21.0-2-4JwamBVgch1x5W0QOEcaXTLV7OIRSPZEwj6ya1","tempo-operator.v0.21.0-2-4wRyhXxfWiZWCybSPC49caRC9r5Lspq8swe9kN"] gvk="apps/v1, Kind=StatefulSet" gvr="apps/v1, Resource=statefulsets" kind=StatefulSet logger=webhooks/resource/validate name=tempo-tempo namespace=tempo-operator operation=CREATE policy=restrict-docker-io-images resource=tempo-operator/StatefulSet/tempo-tempo resource.gvk="apps/v1, Kind=StatefulSet" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info","tempo-operator:tempo-operator-controller-service-cert","tempo-operator:tempo-operator.v0.21.0-2","tempo-operator:tempo-operator.v0.21.0-2-4JwamBVgch1x5W0QOEcaXTLV7OIRSPZEwj6ya1"] uid=3a92c7e1-dfb5-42ab-ac22-5dc9066308c6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=433a94fb-e2d4-4406-a524-a903054442e2"],"authentication.kubernetes.io/pod-name":["tempo-operator-controller-76bcb9f9bd-m2rf5"],"authentication.kubernetes.io/pod-uid":["83a3b270-ffff-4643-a9b4-3f42d2fa92ab"]},"groups":["system:serviceaccounts","system:serviceaccounts:tempo-operator","system:authenticated"],"uid":"b9097c7c-d405-4261-b51f-3b5018b60d37","username":"system:serviceaccount:tempo-operator:tempo-operator-controller-manager"} v=2 2026-07-02T02:21:58Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:statefulset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tempo-tempo-0 namespace=tempo-operator operation=CREATE policy=restrict-docker-io-images resource=tempo-operator/Pod/tempo-tempo-0 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6cfee158-bd75-43a1-9161-5d230dabbd83 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1b2d576e-3345-471f-9076-be21fd78234c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"108b053b-95bb-43a3-8f2a-0f323e8efc97","username":"system:serviceaccount:kube-system:statefulset-controller"} v=2 2026-07-02T02:22:10Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:10 http: TLS handshake error from 10.130.0.2:49358: EOF logger=webhooks/server v=0 2026-07-02T02:22:10Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:10 http: TLS handshake error from 10.128.0.2:54206: EOF logger=webhooks/server v=0 2026-07-02T02:22:10Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:10 http: TLS handshake error from 10.128.0.2:54214: EOF logger=webhooks/server v=0 2026-07-02T02:22:10Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:10 http: TLS handshake error from 10.130.0.2:49362: EOF logger=webhooks/server v=0 2026-07-02T02:22:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:56 http: TLS handshake error from 10.130.0.2:36998: EOF logger=webhooks/server v=0 2026-07-02T02:22:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:56 http: TLS handshake error from 10.128.0.2:44554: EOF logger=webhooks/server v=0 2026-07-02T02:22:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:56 http: TLS handshake error from 10.129.0.2:52764: EOF logger=webhooks/server v=0 2026-07-02T02:22:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:56 http: TLS handshake error from 10.129.0.2:52770: EOF logger=webhooks/server v=0 2026-07-02T02:22:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:56 http: TLS handshake error from 10.128.0.2:44562: EOF logger=webhooks/server v=0 2026-07-02T02:22:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:56 http: TLS handshake error from 10.130.0.2:37004: EOF logger=webhooks/server v=0 2026-07-02T02:22:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:56 http: TLS handshake error from 10.129.0.2:52772: EOF logger=webhooks/server v=0 2026-07-02T02:22:57Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:57 http: TLS handshake error from 10.128.0.2:44602: EOF logger=webhooks/server v=0 2026-07-02T02:22:57Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:22:57 http: TLS handshake error from 10.130.0.2:37020: EOF logger=webhooks/server v=0 2026-07-02T02:23:07Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="apps/v1, Kind=StatefulSet" gvr="apps/v1, Resource=statefulsets" kind=StatefulSet logger=webhooks/resource/validate name=affinity-assistant-800c85fe05 namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/StatefulSet/affinity-assistant-800c85fe05 resource.gvk="apps/v1, Kind=StatefulSet" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c2324802-d478-4ce6-8922-de3bf807f724 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:23:07Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:statefulset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=affinity-assistant-800c85fe05-0 namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/affinity-assistant-800c85fe05-0 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d3c72f27-7461-4729-ab56-90c67c77f66d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1b2d576e-3345-471f-9076-be21fd78234c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"108b053b-95bb-43a3-8f2a-0f323e8efc97","username":"system:serviceaccount:kube-system:statefulset-controller"} v=2 2026-07-02T02:23:07Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-ffrxxnfmor-init-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/buildah-demo-ffrxxnfmor-init-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f350dcc0-8658-49bd-9a52-f7e9887f5c81 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:23:17Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-clvcj namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-clvcj resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=818d2370-8924-4ad7-9a4b-6a0be9437ae4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2e1f46a7-267c-4b05-a05c-50a49b8dc820"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"80348bd6-9110-4c1b-84bf-fcec4fe51c05","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-02T02:23:25Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-ffrxxnfmor-clone-repository-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/buildah-demo-ffrxxnfmor-clone-repository-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f2fb363b-9ad4-47d2-abae-0c9e3ff7b71e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:23:55Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=buildah-demo-ffrxxnfmor-prefetch-dependencies-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=ac0c39e8-3501-4d98-941f-c7688665f634 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:23:55Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=buildah-demo-ffrxxnfmor-prefetch-dependencies-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=362a1c5d-b8e6-490e-8afc-e7ac19e3f79e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:23:55Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-ffrxxnfmor-prefetch-dependencies-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/buildah-demo-ffrxxnfmor-prefetch-dependencies-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=69062a8a-75e8-471e-8f4e-6319cc236090 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:24:03Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-8fh44 namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-8fh44 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=44b9056f-dc52-4cb2-8152-5440cd2a489c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2e1f46a7-267c-4b05-a05c-50a49b8dc820"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"80348bd6-9110-4c1b-84bf-fcec4fe51c05","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-02T02:24:16Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-ffrxxnfmor-build-container-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/buildah-demo-ffrxxnfmor-build-container-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a4ab3aa9-f58f-4730-9bbe-c4df5705c404 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29715985 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29715985 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=95979648-62d2-4781-9d02-9c19229f25f7 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8f36c0b1-bc7a-45f6-a70f-60322d51c2c2"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T02:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29715985-wh4kr namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29715985-wh4kr resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=294bbf12-9744-43bf-bf65-0dd23056943f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=294b2e8e-93f1-4168-b708-8ec58940f4d8"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T02:25:48Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-wldtv namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-wldtv resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=7a09b976-4ecf-4f56-ac9d-437a95c3969e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2e1f46a7-267c-4b05-a05c-50a49b8dc820"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"80348bd6-9110-4c1b-84bf-fcec4fe51c05","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-02T02:26:11Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-ffrxxnfmor-build-image-index-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/buildah-demo-ffrxxnfmor-build-image-index-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a1ed995e-8228-43aa-8118-fa80008061f6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:26:57Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:26:57 http: TLS handshake error from 10.128.0.2:60932: EOF logger=webhooks/server v=0 2026-07-02T02:26:57Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-ffrxxnfmor-apply-tags-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/buildah-demo-ffrxxnfmor-apply-tags-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1692bfd9-4189-435e-9f7e-830134f1f7c4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:26:57Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-ffrxxnfmor-push-dockerfile-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/buildah-demo-ffrxxnfmor-push-dockerfile-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a8170177-6b73-4417-812f-fb639951989b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:27:07Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-fb7af6f0caecb5d478420dddd87eeab1-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=fa26794b-e6f8-4551-ab1d-2d2700221dfd user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:27:07Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-fb7af6f0caecb5d478420dddd87eeab1-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=4a4fba13-391c-45a1-8111-64298b61423b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:27:07Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-fb7af6f0caecb5d478420dddd87eeab1-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/verify-enterprise-contract-fb7af6f0caecb5d478420dddd87eeab1-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=101dcbe9-a4af-4d11-a079-f753f167b883 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:27:30Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-1e627c3c73de708a18d0736fdc0312e0-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=a7ba4277-089b-4afd-ba8c-b292683268cf user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:27:30Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-1e627c3c73de708a18d0736fdc0312e0-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=450a9f57-175e-4558-98f7-b568ea1efbcd user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:27:30Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-1e627c3c73de708a18d0736fdc0312e0-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/verify-enterprise-contract-1e627c3c73de708a18d0736fdc0312e0-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=889c1936-fb77-40cb-ad83-75349e9470b2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:27:45Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-9d7240c384628680a39d32b0cbba20c8-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=bcaa7ffa-a088-4073-8b8d-6a7e1baa7218 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:27:45Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-9d7240c384628680a39d32b0cbba20c8-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=2bc8ac14-e473-4ec0-a1d2-0a49ae06ae83 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:27:45Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-9d7240c384628680a39d32b0cbba20c8-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/verify-enterprise-contract-9d7240c384628680a39d32b0cbba20c8-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=fcbd5d95-cad7-44ff-9d0e-930b69014415 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:27:58Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-c91eebb23f1002a9b7b1f0e47456cea0-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=d8b57928-fc3b-428c-90ab-d95b3e0af081 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:27:58Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-c91eebb23f1002a9b7b1f0e47456cea0-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=9c582d9c-99c8-49e0-abd9-f97768b733d2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:27:58Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-c91eebb23f1002a9b7b1f0e47456cea0-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/verify-enterprise-contract-c91eebb23f1002a9b7b1f0e47456cea0-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=97563185-9765-4906-8703-68ac3215844b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:28:20Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-53069ebe54cd99238b2b027ae3727f0a-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=aa0ea03d-3bcf-4896-85e7-0db1604e9cca user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:28:20Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-53069ebe54cd99238b2b027ae3727f0a-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=4f5858b0-d9bf-47ac-822d-0005f0b91c21 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:28:20Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-53069ebe54cd99238b2b027ae3727f0a-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/verify-enterprise-contract-53069ebe54cd99238b2b027ae3727f0a-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=315020ad-5d56-4315-8e9c-173a2395faab user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:28:33Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-2tqxp namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-2tqxp resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=7e5014f0-086d-49b5-8ee8-c0bd8ed3afca user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2e1f46a7-267c-4b05-a05c-50a49b8dc820"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"80348bd6-9110-4c1b-84bf-fcec4fe51c05","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-02T02:28:34Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-d923b9d6aa6e375cc882162ceae62196-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=644b5196-8cf3-4937-9b9d-a98ffc8e06ad user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:28:34Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-d923b9d6aa6e375cc882162ceae62196-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=33b1a1d8-3c42-4c2f-ba18-c4781e514b0e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:28:34Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-d923b9d6aa6e375cc882162ceae62196-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/verify-enterprise-contract-d923b9d6aa6e375cc882162ceae62196-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=27a3d01e-33f4-4286-b7ee-586e3ff38403 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:28:52Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-f05a8fd4d4590a32c367b41cc55592bc-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=e120eee3-7529-43ec-9dff-3f2b4dd2d1fe user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:28:53Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-f05a8fd4d4590a32c367b41cc55592bc-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=c003943f-ae9c-4c51-9ebf-99c5ba3300bd user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:28:53Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-f05a8fd4d4590a32c367b41cc55592bc-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/verify-enterprise-contract-f05a8fd4d4590a32c367b41cc55592bc-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=70562228-74c4-4c12-8f6a-ebc4daf56731 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:29:23Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-160edd7553ed2c65b9a1b7c51c0eea30-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=8647bf4e-d7fc-4232-bdca-2717d5c07acc user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:29:24Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-160edd7553ed2c65b9a1b7c51c0eea30-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=44e3dcf6-67b5-4006-bd07-a2310e9cb505 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:29:24Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-160edd7553ed2c65b9a1b7c51c0eea30-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/verify-enterprise-contract-160edd7553ed2c65b9a1b7c51c0eea30-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=70626fc5-0f69-4129-bba1-b6bbdf94ce6c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64c287eb-8417-4bdc-9d9a-511960bb443c"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["d943e233-817b-448e-901d-033f073c3f2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:29:37Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-7d062f4c38b11447383f976c2788b84d-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=c356b8e5-c3bd-4cc2-be9f-ae7e9c57fc62 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:29:38Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-7d062f4c38b11447383f976c2788b84d-pod namespace=chains-e2e-nyog operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=d8ed4846-efc7-4867-9e9c-0a873bc5f83e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:29:38Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-7d062f4c38b11447383f976c2788b84d-pod namespace=chains-e2e-nyog operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nyog/Pod/verify-enterprise-contract-7d062f4c38b11447383f976c2788b84d-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f6edbbac-d5b1-41ed-bbb4-72c4aa2569a3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=e29320ff-1951-4520-a554-b8851adae6d1"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["775893a8-b508-406c-a26b-65096e8e396b"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"c94b9a4c-b96e-4e29-a5b5-e5245c09ef6a","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-02T02:29:53Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:53 http: TLS handshake error from 10.130.0.2:47004: EOF logger=webhooks/server v=0 2026-07-02T02:29:53Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:53 http: TLS handshake error from 10.128.0.2:38082: EOF logger=webhooks/server v=0 2026-07-02T02:29:53Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:53 http: TLS handshake error from 10.128.0.2:38068: EOF logger=webhooks/server v=0 2026-07-02T02:29:53Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:53 http: TLS handshake error from 10.130.0.2:47012: EOF logger=webhooks/server v=0 2026-07-02T02:29:53Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:53 http: TLS handshake error from 10.130.0.2:47008: EOF logger=webhooks/server v=0 2026-07-02T02:29:53Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:53 http: TLS handshake error from 10.129.0.2:36278: EOF logger=webhooks/server v=0 2026-07-02T02:29:53Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:53 http: TLS handshake error from 10.128.0.2:38088: EOF logger=webhooks/server v=0 2026-07-02T02:29:53Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:53 http: TLS handshake error from 10.130.0.2:47036: EOF logger=webhooks/server v=0 2026-07-02T02:29:53Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:53 http: TLS handshake error from 10.128.0.2:38100: EOF logger=webhooks/server v=0 2026-07-02T02:29:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:56 http: TLS handshake error from 10.129.0.2:36292: EOF logger=webhooks/server v=0 2026-07-02T02:29:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:56 http: TLS handshake error from 10.129.0.2:36294: EOF logger=webhooks/server v=0 2026-07-02T02:29:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:56 http: TLS handshake error from 10.129.0.2:36298: EOF logger=webhooks/server v=0 2026-07-02T02:29:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:56 http: TLS handshake error from 10.128.0.2:38114: EOF logger=webhooks/server v=0 2026-07-02T02:29:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:56 http: TLS handshake error from 10.129.0.2:36304: EOF logger=webhooks/server v=0 2026-07-02T02:29:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:56 http: TLS handshake error from 10.129.0.2:36314: EOF logger=webhooks/server v=0 2026-07-02T02:29:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:56 http: TLS handshake error from 10.130.0.2:47048: EOF logger=webhooks/server v=0 2026-07-02T02:29:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:56 http: TLS handshake error from 10.129.0.2:36324: EOF logger=webhooks/server v=0 2026-07-02T02:29:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:56 http: TLS handshake error from 10.128.0.2:38132: EOF logger=webhooks/server v=0 2026-07-02T02:29:56Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:56 http: TLS handshake error from 10.129.0.2:36334: EOF logger=webhooks/server v=0 2026-07-02T02:29:57Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:57 http: TLS handshake error from 10.128.0.2:38148: EOF logger=webhooks/server v=0 2026-07-02T02:29:57Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:57 http: TLS handshake error from 10.129.0.2:36348: EOF logger=webhooks/server v=0 2026-07-02T02:29:58Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:58 http: TLS handshake error from 10.128.0.2:38158: EOF logger=webhooks/server v=0 2026-07-02T02:29:58Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:58 http: TLS handshake error from 10.129.0.2:36356: EOF logger=webhooks/server v=0 2026-07-02T02:29:58Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:58 http: TLS handshake error from 10.128.0.2:38168: EOF logger=webhooks/server v=0 2026-07-02T02:29:58Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:58 http: TLS handshake error from 10.129.0.2:36362: EOF logger=webhooks/server v=0 2026-07-02T02:29:58Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:58 http: TLS handshake error from 10.128.0.2:38174: EOF logger=webhooks/server v=0 2026-07-02T02:29:58Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:58 http: TLS handshake error from 10.128.0.2:38190: EOF logger=webhooks/server v=0 2026-07-02T02:29:59Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:59 http: TLS handshake error from 10.128.0.2:38192: EOF logger=webhooks/server v=0 2026-07-02T02:29:59Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:59 http: TLS handshake error from 10.128.0.2:38202: EOF logger=webhooks/server v=0 2026-07-02T02:29:59Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:29:59 http: TLS handshake error from 10.128.0.2:38194: EOF logger=webhooks/server v=0 2026-07-02T02:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29715990 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29715990 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5cfe3877-7587-4b42-b2aa-920cb6f289fa user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8f36c0b1-bc7a-45f6-a70f-60322d51c2c2"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T02:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29715990 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29715990 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=de082196-3de2-46b6-8d42-1e5719a27021 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8f36c0b1-bc7a-45f6-a70f-60322d51c2c2"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T02:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29715990-hqdld namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29715990-hqdld resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9ca0718a-3544-4a2b-ab33-f550534f7059 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=294b2e8e-93f1-4168-b708-8ec58940f4d8"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T02:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29715990-xpspd namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29715990-xpspd resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1eb7d169-1b36-43e6-815e-6485dd1df1d3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=294b2e8e-93f1-4168-b708-8ec58940f4d8"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T02:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29715995 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29715995 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f6e82341-1358-4831-8cc1-e1dfbb2200aa user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8f36c0b1-bc7a-45f6-a70f-60322d51c2c2"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T02:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29715995-2lgz5 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29715995-2lgz5 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f36d9f1c-5c0b-480f-90b5-ed85ed1e0694 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=294b2e8e-93f1-4168-b708-8ec58940f4d8"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T02:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716000 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29716000 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=69807270-46d7-4739-942f-cb69299c8c11 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8f36c0b1-bc7a-45f6-a70f-60322d51c2c2"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T02:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716000 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716000 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ee12a8c7-904c-4bf3-b109-e4f850b92fc3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8f36c0b1-bc7a-45f6-a70f-60322d51c2c2"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T02:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716000-c2d7c namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716000-c2d7c resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b500aabf-d6de-4b12-90b2-cc83c69842a4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=294b2e8e-93f1-4168-b708-8ec58940f4d8"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T02:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716000-rvv6p namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29716000-rvv6p resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1a6e1b8a-12c4-4314-828f-2264fc38d38c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=294b2e8e-93f1-4168-b708-8ec58940f4d8"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T02:44:15Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-6w7k4 namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-6w7k4 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=10da4e15-b30d-4347-9029-ddfb6aae21b0 user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-07-02T02:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716005 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716005 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=fc67c2ff-a611-48e0-a5e0-2be3f7c263f4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8f36c0b1-bc7a-45f6-a70f-60322d51c2c2"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T02:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716005-v7csx namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716005-v7csx resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=de90bd32-f9a0-4f70-b6dc-767ff5094b9b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=294b2e8e-93f1-4168-b708-8ec58940f4d8"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T02:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716010 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29716010 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6a61b877-8d68-431f-8fab-e3e1bfb6edfc user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8f36c0b1-bc7a-45f6-a70f-60322d51c2c2"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T02:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716010 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716010 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=848b6cf8-8bd8-496c-a3fe-f3c86e927a76 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8f36c0b1-bc7a-45f6-a70f-60322d51c2c2"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T02:50:00Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 02:50:00 http: TLS handshake error from 10.130.0.2:42586: EOF logger=webhooks/server v=0 2026-07-02T02:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716010-rnjzw namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716010-rnjzw resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a7af7b6f-36b3-40ec-bf79-13de030d869a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=294b2e8e-93f1-4168-b708-8ec58940f4d8"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T02:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716010-5xvhg namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29716010-5xvhg resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=96b1aae8-4de7-412f-9771-1955ab306ef3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=294b2e8e-93f1-4168-b708-8ec58940f4d8"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T02:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716015 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716015 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=53ba9058-997d-4d60-a5f0-18dc70912b80 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T02:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716015-62hdv namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716015-62hdv resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e51699c7-a301-4773-a75e-cca0a5ca08f2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=namespace-claim-cleaner-29716020 namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Job/namespace-claim-cleaner-29716020 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d99cca2f-f39f-4490-8527-ecf1aa2523ad user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=image-controller-notification-resetter-cronjob-29716020 namespace=image-controller operation=CREATE policy=restrict-docker-io-images resource=image-controller/Job/image-controller-notification-resetter-cronjob-29716020 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=538f4c71-a3f3-4469-ad70-c1dd62662d4b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716020 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716020 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f6638f01-5f05-4027-b78d-853c045768af user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716020 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29716020 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=21a15eaf-d567-4558-88a4-b9ab6cecba24 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=namespace-claim-cleaner-29716020-mnlqx namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Pod/namespace-claim-cleaner-29716020-mnlqx resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b9a1fd2d-8e30-4276-8953-ef5163fd91f9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=image-controller-notification-resetter-cronjob-29716020-8nb47 namespace=image-controller operation=CREATE policy=restrict-docker-io-images resource=image-controller/Pod/image-controller-notification-resetter-cronjob-29716020-8nb47 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ba47c199-d0a2-4599-adbb-2898e3b9dd41 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716020-sj94f namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29716020-sj94f resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0aeb9089-af09-4be0-87ce-d09c164ccdc5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716020-778qd namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716020-778qd resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8bc8325c-038d-4616-9e18-c55b440d3101 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716025 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716025 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8cf8af3b-48ce-436d-8791-59e899235131 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716025-ft58h namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716025-ft58h resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=13b8faa5-5b7d-44e5-9a9a-c15fe651e068 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716030 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29716030 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0e4ac10b-5630-4a1f-b159-7d866732745d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716030 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716030 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=00f93708-be2e-41ca-a507-00494f5ed5bd user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=cleanup-timed-out-pipelineruns-internal-requests-29716030 namespace=release-service operation=CREATE policy=restrict-docker-io-images resource=release-service/Job/cleanup-timed-out-pipelineruns-internal-requests-29716030 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b025dba9-0eb2-439d-98f4-665ec31ccba0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716030-gsl5p namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29716030-gsl5p resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b8ff9297-7395-491e-b104-97f935c7c36f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=cleanup-timed-out-pipelineruns-internal-requests-29716030-7r646 namespace=release-service operation=CREATE policy=restrict-docker-io-images resource=release-service/Pod/cleanup-timed-out-pipelineruns-internal-requests-29716030-7r646 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f7217d06-adfd-40b4-931c-8e63e32254c9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716030-cqcq4 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716030-cqcq4 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ab63b27a-4275-4d74-ad0c-86cf6122ceea user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:13:56Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=oauth-secret-generator namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Job/oauth-secret-generator resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=07df7f9a-6dd9-4164-80ff-f6173f21d845 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=67475f2b-4e64-4f8c-9da3-4105014b0374"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["c8283afb-8240-46f1-9b41-44ff58008bf2"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"e9cf1689-12a4-446a-bba4-3ff29e2c74bb","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-07-02T03:13:56Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=oauth-secret-generator-kpg8q namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/oauth-secret-generator-kpg8q resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=3573c805-8b8a-4e33-b6a5-bcc41cf5c6a6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:14:15Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-4mm5f namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-4mm5f resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=392f4349-94b6-4068-9b5f-3bfbbfb3a594 user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-07-02T03:14:15Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=image-rbac-proxy-84b6b5b976-zqkmw namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/image-rbac-proxy-84b6b5b976-zqkmw resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f4c5b7db-f75d-4c8e-a058-a8e0e10d106c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2ba8e69e-fb83-4312-a3ce-7964464599bd"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"80348bd6-9110-4c1b-84bf-fcec4fe51c05","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-02T03:14:15Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=dex-75b8f4f8c9-bl76v namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/dex-75b8f4f8c9-bl76v resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=30849a20-2637-4fed-b784-41f81a6301b5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2ba8e69e-fb83-4312-a3ce-7964464599bd"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"80348bd6-9110-4c1b-84bf-fcec4fe51c05","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-02T03:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716035 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716035 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1a64aceb-4fc7-4346-900c-2e737bb62991 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716035-4bcf6 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716035-4bcf6 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2a3125bf-1c9e-4064-acee-957cf1870497 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:16:31Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 03:16:31 http: TLS handshake error from 10.130.0.2:60774: EOF logger=webhooks/server v=0 2026-07-02T03:16:32Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 03:16:32 http: TLS handshake error from 10.129.0.2:33460: EOF logger=webhooks/server v=0 2026-07-02T03:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716040 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716040 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=bb73db2f-e1fc-48c5-bc43-b4e03859581d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716040 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29716040 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e3bcac02-19b5-4b5a-98e9-9ed22e633d73 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716040-dcpx9 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29716040-dcpx9 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b99e98d0-ab1d-4973-b90a-31660347a5ad user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716040-zts96 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716040-zts96 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=313983a5-ad0d-492f-a545-b2fc2d6e341e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716045 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716045 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=86d90e7c-0a79-4826-bc14-8b842fae39f9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716045-zcjk6 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716045-zcjk6 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1518284f-b904-4efa-b4d1-677002796e11 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716050 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716050 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=77b23746-94bd-498d-9442-ad2462d613ad user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716050 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29716050 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c8a78023-c38f-4209-a2cd-c16e21acdd4b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716050-mqrq5 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716050-mqrq5 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9c370bdc-3c6c-4e84-80c5-ad12f6adf353 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716050-6lt4b namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29716050-6lt4b resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4f41ca13-880c-4770-a631-6b61da49b5c6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716055 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716055 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=65215e4d-14be-45f0-8370-0d841b87deaf user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716055-q9q7t namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716055-q9q7t resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=18f9d9af-bd72-4019-8edb-9600d6785e65 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716060 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29716060 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=59b98e1a-dc98-4e5a-9e55-f8d2e5a8e73d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716060 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716060 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2a09fa8a-5539-4fd0-b368-dd486e5592ab user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a265d84f-4503-4339-8c03-95e1ecd0f567"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:40:00Z INF kyverno/pkg/logging/log.go:180 > 2026/07/02 03:40:00 http: TLS handshake error from 10.130.0.2:39532: EOF logger=webhooks/server v=0 2026-07-02T03:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716060-zb79p namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29716060-zb79p resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e958562e-442c-4e65-ab96-3228ccb4adb6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716060-t62dr namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716060-t62dr resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1d8cd08a-4ba1-40b9-824e-d0b436a49349 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=37a544f2-e626-4764-8457-dfc80c6fd9c9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:44:15Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-4t8nj namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-4t8nj resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=bd8593bb-1399-48f9-a7e0-eb6d99fc4651 user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-07-02T03:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716065 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716065 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=eda9caf0-8849-4d9e-9a1f-72864c628b52 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=63d3fc85-368e-46c5-93f8-186b57e52b04"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716065-2zcb5 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716065-2zcb5 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=562463f6-7fa5-4297-af24-839a97e74eb9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=3dc8bd07-071b-459c-8ac7-21bbdd839da6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716070 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29716070 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=31629af5-4be6-4254-a2db-8215e108c9d6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=63d3fc85-368e-46c5-93f8-186b57e52b04"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29716070 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29716070 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=895b0bea-7f22-4afd-93e0-ffc6b79b1e34 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=63d3fc85-368e-46c5-93f8-186b57e52b04"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61bfe6ff-735d-4a82-8c3f-4943839ed460","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-02T03:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29716070-jjlk8 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29716070-jjlk8 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=dac5a926-4022-4fd0-a649-9e4c4f6e94d7 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=3dc8bd07-071b-459c-8ac7-21bbdd839da6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-02T03:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29716070-7vlc8 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29716070-7vlc8 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ee0656fe-1890-436d-9af6-08044ce657d2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=3dc8bd07-071b-459c-8ac7-21bbdd839da6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"451fa39d-a30a-485e-9f13-e5c5139d6bc2","username":"system:serviceaccount:kube-system:job-controller"} v=2