2026-07-03T14:11:45Z TRC kyverno/pkg/version/version.go:49 > version hash=--- logger=setup/version v=2 version=1.25.8 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > add_dir_header=false logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > admissionReports=false logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > allowInsecureRegistry=false logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > alsologtostderr=false logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > autoDeleteWebhooks=false logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > autoUpdateWebhooks=true logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > backgroundServiceAccountName=system:serviceaccount:konflux-kyverno:kyverno-background-controller logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > caSecretName=konflux-kyverno-svc.konflux-kyverno.svc.kyverno-tls-ca logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > cleanupServerPort=9443 logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > clientRateLimitBurst=200 logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > clientRateLimitQPS=100 logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > controllerRuntimeMetricsAddress=:8080 logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > crdWatcher=false logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > disableLogColor=false logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > disableMetrics=false logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > dumpPatches= logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > dumpPayload=false logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > enableConfigMapCaching=true logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > enableDeferredLoading= logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > enablePolicyException=false logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > enableReporting= logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > enableTracing=false logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > enableTuf=false logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > eventsRateLimitBurst=2000 logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > eventsRateLimitQPS=1000 logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > exceptionNamespace= logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > forceFailurePolicyIgnore= logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > generateMutatingAdmissionPolicy= logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > generateValidatingAdmissionPolicy= logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > imagePullSecrets= logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheEnabled=true logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheMaxSize=1000 logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheTTLDuration=1h0m0s logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > kubeconfig= logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > leaderElectionRetryPeriod=26s logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > log_backtrace_at=:0 logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > log_dir= logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > log_file= logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > log_file_max_size=1800 logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag loggingFormat=text v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag loggingtsFormat=default v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag logtostderr=true v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAPICallResponseLength=2000000 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAdmissionReports=1000 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAuditCapacity=1000 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAuditWorkers=8 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxQueuedEvents=1000 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag metricsPort=8000 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag omitEvents=PolicyApplied,PolicySkipped v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag one_output=false v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag otelCollector=opentelemetrycollector.kyverno.svc.cluster.local v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag otelConfig=prometheus v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profile=false v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profileAddress= v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profilePort=6060 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag protectManagedResources= v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag registryCredentialHelpers=default,google,amazon,azure,github v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag renewBefore=360h0m0s v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag reportsServiceAccountName= v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag resyncPeriod=15m0s v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag serverIP= v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag servicePort=443 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag skip_headers=false v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag skip_log_headers=false v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag stderrthreshold=2 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tlsSecretName=konflux-kyverno-svc.konflux-kyverno.svc.kyverno-tls-pair v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingAddress= v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingCreds= v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingPort=4317 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag transportCreds= v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufMirror=https://tuf-repo-cdn.sigstore.dev v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufRoot= v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufRootRaw= v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 vmodule= 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookRegistrationTimeout=2m0s 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookServerPort=9443 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookTimeout=10 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/maxprocs.go:12 > setup maxprocs... logger=setup/maxprocs v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/signal.go:16 > setup signals... logger=setup/signals v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/kube-client qps=100 v=2 2026-07-03T14:11:45Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=InformerResourceVersion logger=klog v=1 2026-07-03T14:11:45Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=true feature=InOrderInformers logger=klog v=1 2026-07-03T14:11:45Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=WatchListClient logger=klog v=1 2026-07-03T14:11:45Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=ClientsAllowCBOR logger=klog v=1 2026-07-03T14:11:45Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=ClientsPreferCBOR logger=klog v=1 2026-07-03T14:11:45Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/metrics.go:18 > setup metrics... collector=opentelemetrycollector.kyverno.svc.cluster.local creds= logger=setup/metrics otel=prometheus port=8000 v=2 2026-07-03T14:11:45Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:417 > defaultRegistry configured defaultRegistry=docker.io logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:433 > enableDefaultRegistryMutation configured enableDefaultRegistryMutation=true logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:442 > excludedGroups configured excludeGroups=["system:nodes"] includeGroups=[] logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:447 > excludeUsernames not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:455 > excludeRoles not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:463 > excludeClusterRoles not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:479 > generateSuccessEvents configured generateSuccessEvents=false logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:493 > webhooks configured logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 webhooks="{\"namespaceSelector\":{\"matchExpressions\":[{\"key\":\"kubernetes.io/metadata.name\",\"operator\":\"NotIn\",\"values\":[\"kube-system\"]},{\"key\":\"kubernetes.io/metadata.name\",\"operator\":\"NotIn\",\"values\":[\"konflux-kyverno\"]}],\"matchLabels\":null}}" 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:507 > webhookAnnotations configured logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 webhookAnnotations="{\"admissions.enforcer/disabled\":\"true\"}" 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:513 > webhookLabels not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:527 > matchConditions not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:548 > enableDefaultRegistryMutation configured enableDefaultRegistryMutation=true logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-03T14:11:45Z TRC kyverno/pkg/config/config.go:563 > maxContextSize not set, using default default=2097152 logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/registry.go:18 > setup registry client... insecure=false logger=setup/registry-client secrets= v=2 2026-07-03T14:11:45Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/imageverifycache.go:10 > setup image verify cache... enabled=true logger=setup/image-verify-cache maxsize=1000 ttl=1h0m0s v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/kube-client qps=100 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/client.go:60 > create kyverno client... burst=200 kubeconfig= logger=setup/kyverno-client qps=100 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/client.go:68 > create dynamic client... burst=200 kubeconfig= logger=setup/dynamic-client qps=100 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/client.go:84 > create apiserver client... burst=200 kubeconfig= logger=setup/apiserver-client qps=100 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/client.go:76 > create metadata client... burst=200 kubeconfig= logger=setup/metadata-client qps=100 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/client.go:92 > create the kyverno dynamic client... burst=200 kubeconfig= logger=setup/d-client qps=100 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/client.go:100 > create the events client... burst=200 kubeconfig= logger=setup/events-client qps=100 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/events-client/kube-client qps=100 v=2 2026-07-03T14:11:45Z TRC kyverno/cmd/internal/reporting.go:13 > setting up reporting... enableReporting= generate=false imageVerify=false logger=setup/setup-reporting mutate=false mutateExisiting=false v=2 validate=false 2026-07-03T14:11:45Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-07-03T14:11:45Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-07-03T14:11:45Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Deployment v=2 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/engine.go:65 > setup exception selector... enablePolicyException=false exceptionNamespace= logger=setup/exception-selector v=2 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/engine.go:94 > setup config map resolver... enableConfigMapCaching=true logger=setup/configmap-resolver v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/engine.go:46 > setup engine... logger=setup/engine v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Deployment v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2alpha1.GlobalContextEntry v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterPolicy v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Policy v=2 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/metrics/server/server.go:208 > Starting metrics server logger=controller-runtime/metrics v=0 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/metrics/server/server.go:247 > Serving metrics server bindAddress=:8080 logger=controller-runtime/metrics secure=false v=0 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy source="kind source: *v1alpha1.ValidatingPolicy" v=0 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy source="kind source: *v1alpha1.MutatingPolicy" v=0 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy source="kind source: *v1alpha1.ImageValidatingPolicy" v=0 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.PolicyException v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.GeneratingPolicy v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2.UpdateRequest v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Namespace v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterRoleBinding v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ValidatingPolicy v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ImageValidatingPolicy v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.MutatingPolicy v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.RoleBinding v=2 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/leaderelection/leaderelection.go:257 > attempting to acquire leader lease konflux-kyverno/kyverno... logger=klog v=0 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/controllers name=policycache-controller v=2 workers=3 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup name=kyverno-events v=2 workers=3 2026-07-03T14:11:46Z TRC kyverno/pkg/event/controller.go:106 > start logger=EventGenerator v=2 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup name=global-context v=2 workers=1 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/leaderelection/leaderelection.go:271 > successfully acquired lease konflux-kyverno/kyverno logger=klog v=0 2026-07-03T14:11:46Z TRC kyverno/pkg/leaderelection/leaderelection.go:83 > started leading id=kyverno-admission-controller-5cbb799dc8-rcwkm logger=setup/leader-election v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ValidatingPolicy v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.PolicyException v=2 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy v=0 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy v=0 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy v=0 worker count=1 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy v=0 worker count=1 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy v=0 2026-07-03T14:11:46Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy v=0 worker count=1 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.MutatingPolicy v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.GeneratingPolicy v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingAdmissionPolicy v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Policy v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2.PolicyException v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterPolicy v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Lease v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ImageValidatingPolicy v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingAdmissionPolicyBinding v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.MutatingWebhookConfiguration v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingWebhookConfiguration v=2 2026-07-03T14:11:46Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterRole v=2 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=admissionpolicy-generator v=2 workers=2 2026-07-03T14:11:46Z TRC kyverno/pkg/utils/controller/run.go:58 > starting ... logger=admissionpolicy-generator v=2 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=exception-webhook-controller v=2 workers=1 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=global-context-webhook-controller v=2 workers=1 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=celexception-webhook-controller v=2 workers=1 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=certmanager-controller v=2 workers=1 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=webhook-controller v=2 workers=2 2026-07-03T14:11:46Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=status-controller v=2 workers=3 2026-07-03T14:14:14Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:14:14 http: TLS handshake error from 10.130.0.2:55360: EOF logger=webhooks/server v=0 2026-07-03T14:14:14Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:14:14 http: TLS handshake error from 10.129.0.2:36444: EOF logger=webhooks/server v=0 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpmonitoring uid=31b9b958-1557-4463-b7cd-935f5fb0a210 v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=init-ns-kubearchiveconfig uid=8470734e-8733-41b3-b5c8-4fe2fbcb0a2d v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpmonitoring type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-rbcm uid=00a7bb1f-ce8e-4157-8ebe-27004e2a6a3c v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=init-ns-kubearchiveconfig type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-rbcm type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpingress type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpingress uid=a67be3dd-145b-410f-a1d0-4239b9a64817 v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpconsole uid=d8e446cb-85f6-40af-8087-33a714ccc255 v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpconsole type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-olm type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-olm uid=435ec852-9f39-4a24-9871-cc6d12dcfc2d v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=integration-init-ns-integration uid=66909048-10c1-4ea5-a6e8-f61ced81b8ed v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=integration-init-ns-integration type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-samenamespace type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-samenamespace uid=9e9ba1e4-4ad3-4eb6-8f4f-b913da77d242 v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-generate-konflux-viewer-access type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-generate-konflux-viewer-access uid=81731f44-4c89-4dbd-9d5f-5377c6b3bdd0 v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-validate-restrict-binding-system-authenticated uid=ad711088-6245-47a8-8d0e-f5e1191fb56a v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-validate-restrict-binding-system-authenticated type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-validate-restrict-binding-sysauth-releng type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-validate-restrict-binding-sysauth-releng uid=d736f286-4031-453d-8577-335862b31911 v=2 2026-07-03T14:14:14Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"konflux-rbac-validate-restrict-binding-system-authenticated\": the object has been modified; please apply your changes to the latest version and try again" konflux-rbac-validate-restrict-binding-system-authenticated=status 2026-07-03T14:14:14Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"konflux-rbac-validate-restrict-binding-sysauth-releng\": the object has been modified; please apply your changes to the latest version and try again" konflux-rbac-validate-restrict-binding-sysauth-releng=status 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=restrict-binding-system-groups type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=restrict-binding-system-groups uid=c0578406-c776-4b29-adaf-57262a61ac19 v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=tekton-taskrun-resource-policy uid=90ecad1e-d5fd-4411-90bb-66fe73bf8822 v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=tekton-taskrun-resource-policy type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=restrict-docker-io-images type=ClusterPolicy v=2 2026-07-03T14:14:14Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=restrict-docker-io-images uid=72bb7985-2445-458b-9e4d-2960edc241f2 v=2 2026-07-03T14:14:14Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"restrict-binding-system-groups\": the object has been modified; please apply your changes to the latest version and try again" restrict-binding-system-groups=status 2026-07-03T14:14:14Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"restrict-docker-io-images\": the object has been modified; please apply your changes to the latest version and try again" restrict-docker-io-images=status 2026-07-03T14:14:19Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=bootstrap-tenant-namespace-queue uid=46ae2be1-8149-4bdc-a666-a45348951fc1 v=2 2026-07-03T14:14:19Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=bootstrap-tenant-namespace-queue type=ClusterPolicy v=2 2026-07-03T14:14:21Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","minio-operator-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=StatefulSet" gvr="apps/v1, Resource=statefulsets" kind=StatefulSet logger=webhooks/resource/validate name=oadp-minio-storage-pool-0 namespace=openshift-adp operation=CREATE policy=restrict-docker-io-images resource=openshift-adp/StatefulSet/oadp-minio-storage-pool-0 resource.gvk="apps/v1, Kind=StatefulSet" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=abdae2d9-f6ad-4735-a563-43b39cab4107 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=36dcd255-33b2-46b9-89cc-c8555204bb39"],"authentication.kubernetes.io/pod-name":["minio-operator-54646886cb-lf6x7"],"authentication.kubernetes.io/pod-uid":["976fb935-e032-4ace-b785-f3cba4047271"]},"groups":["system:serviceaccounts","system:serviceaccounts:minio-operator","system:authenticated"],"uid":"f9f2c04b-9f72-4b7b-ac90-ae195168b520","username":"system:serviceaccount:minio-operator:minio-operator"} v=2 2026-07-03T14:14:21Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:14:21 http: TLS handshake error from 10.128.0.2:53436: EOF logger=webhooks/server v=0 2026-07-03T14:14:21Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:statefulset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=oadp-minio-storage-pool-0-0 namespace=openshift-adp operation=CREATE policy=restrict-docker-io-images resource=openshift-adp/Pod/oadp-minio-storage-pool-0-0 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ed4d9cb2-d9de-489d-a087-2519db468ede user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=efc07d9a-420a-444b-a689-e74bcec82b48"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61081088-df98-4970-8171-5160775198de","username":"system:serviceaccount:kube-system:statefulset-controller"} v=2 2026-07-03T14:14:23Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=create-velero-bucket namespace=openshift-adp operation=CREATE policy=restrict-docker-io-images resource=openshift-adp/Job/create-velero-bucket resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=d1cb2d51-d9fd-4687-b605-48faaed022d9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5ef7990b-71b9-4a61-b15a-956f2f02f2d9"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["4ef5b9d4-c55e-4b27-a6e5-31080f3efd5d"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"96a5b0d3-e238-401b-b4da-7accae891fe8","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-07-03T14:14:23Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=create-velero-bucket-k5dzf namespace=openshift-adp operation=CREATE policy=restrict-docker-io-images resource=openshift-adp/Pod/create-velero-bucket-k5dzf resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9a3f76f6-9392-42a6-a51d-942f13e98b62 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64707764-661a-40aa-8127-6dfd4ef350e6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:14:23Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=tekton-chains-signing-secret namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Job/tekton-chains-signing-secret resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=103ff2ef-0d6b-4876-a635-0eff6f6e475f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5ef7990b-71b9-4a61-b15a-956f2f02f2d9"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["4ef5b9d4-c55e-4b27-a6e5-31080f3efd5d"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"96a5b0d3-e238-401b-b4da-7accae891fe8","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-07-03T14:14:23Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-chains-signing-secret-74s9j namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-chains-signing-secret-74s9j resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b5e1e851-7011-4545-8e21-c52f08bd06c2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64707764-661a-40aa-8127-6dfd4ef350e6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:14:50Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","oadp-operator.v1.4.10-9GNK7neB7QzjkfeNPcFUJUMLdO46z70CQS60b9","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=velero namespace=openshift-adp operation=CREATE policy=restrict-docker-io-images resource=openshift-adp/Deployment/velero resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-adp:oadp-operator.v1.4.10","openshift-adp:oadp-operator.v1.4.10-op-2JFmLINt0QdbqDAI2gqCSw5cdFfGT9ylQg7wNh","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=25e9304d-cf9a-4aa8-adce-cdd8e33df955 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=7af4f036-31fa-44f9-a532-ce8f1b575df2"],"authentication.kubernetes.io/pod-name":["openshift-adp-controller-manager-6fddd7d758-g8bd4"],"authentication.kubernetes.io/pod-uid":["c56907b3-a75c-4061-9603-460d64e182c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-adp","system:authenticated"],"uid":"e9a00ef8-09a7-42cf-97fe-dc255d3de8a6","username":"system:serviceaccount:openshift-adp:openshift-adp-controller-manager"} v=2 2026-07-03T14:14:50Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=velero-75d4c77d6d-bq25r namespace=openshift-adp operation=CREATE policy=restrict-docker-io-images resource=openshift-adp/Pod/velero-75d4c77d6d-bq25r resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a74f684a-3264-40cc-9be8-aa6c04c1ea1a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=744a5e4a-44d5-4cab-bcf1-e7cdc8ca4d61"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"e4d3c968-a7e1-4798-a885-212e427428e8","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-03T14:14:50Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","oadp-operator.v1.4.10-9GNK7neB7QzjkfeNPcFUJUMLdO46z70CQS60b9","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=DaemonSet" gvr="apps/v1, Resource=daemonsets" kind=DaemonSet logger=webhooks/resource/validate name=node-agent namespace=openshift-adp operation=CREATE policy=restrict-docker-io-images resource=openshift-adp/DaemonSet/node-agent resource.gvk="apps/v1, Kind=DaemonSet" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-adp:oadp-operator.v1.4.10","openshift-adp:oadp-operator.v1.4.10-op-2JFmLINt0QdbqDAI2gqCSw5cdFfGT9ylQg7wNh","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a558147c-0da0-4875-8813-5cc343065d03 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=7af4f036-31fa-44f9-a532-ce8f1b575df2"],"authentication.kubernetes.io/pod-name":["openshift-adp-controller-manager-6fddd7d758-g8bd4"],"authentication.kubernetes.io/pod-uid":["c56907b3-a75c-4061-9603-460d64e182c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-adp","system:authenticated"],"uid":"e9a00ef8-09a7-42cf-97fe-dc255d3de8a6","username":"system:serviceaccount:openshift-adp:openshift-adp-controller-manager"} v=2 2026-07-03T14:14:50Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:daemon-set-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=node-agent-99rln namespace=openshift-adp operation=CREATE policy=restrict-docker-io-images resource=openshift-adp/Pod/node-agent-99rln resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=da91a508-6380-4514-9905-4095b5ac58e1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=6f9af9b1-15eb-4355-a541-63112f1c8bba"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"3c7e7ec9-b81a-4f98-963f-715af39e6708","username":"system:serviceaccount:kube-system:daemon-set-controller"} v=2 2026-07-03T14:14:50Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:daemon-set-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=node-agent-crs7m namespace=openshift-adp operation=CREATE policy=restrict-docker-io-images resource=openshift-adp/Pod/node-agent-crs7m resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4dd92fba-7379-4559-85cd-c28e5294527e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=6f9af9b1-15eb-4355-a541-63112f1c8bba"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"3c7e7ec9-b81a-4f98-963f-715af39e6708","username":"system:serviceaccount:kube-system:daemon-set-controller"} v=2 2026-07-03T14:14:50Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:daemon-set-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=node-agent-ng2t7 namespace=openshift-adp operation=CREATE policy=restrict-docker-io-images resource=openshift-adp/Pod/node-agent-ng2t7 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9d7e5c88-4f70-4e88-91f9-ba5f92a33fc1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=6f9af9b1-15eb-4355-a541-63112f1c8bba"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"3c7e7ec9-b81a-4f98-963f-715af39e6708","username":"system:serviceaccount:kube-system:daemon-set-controller"} v=2 2026-07-03T14:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718135 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718135 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8a279eb3-e156-4c09-a5dd-6046a3dd9157 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=81d2586a-c6d6-4b3f-b9ed-9eae6b16c64a"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718135-z5zzm namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718135-z5zzm resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5826623a-ae1b-4f59-9b37-428cfa2fbd5c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64707764-661a-40aa-8127-6dfd4ef350e6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:15:10Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:15:10 http: TLS handshake error from 10.130.0.2:45978: EOF logger=webhooks/server v=0 2026-07-03T14:17:09Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=tekton-results-watcher namespace=tekton-results operation=CREATE policy=restrict-docker-io-images resource=tekton-results/Deployment/tekton-results-watcher resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=aa4a91d4-5001-4286-8cd1-99b942c2c827 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5ef7990b-71b9-4a61-b15a-956f2f02f2d9"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["4ef5b9d4-c55e-4b27-a6e5-31080f3efd5d"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"96a5b0d3-e238-401b-b4da-7accae891fe8","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-07-03T14:17:09Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-results-watcher-55667bb668-756b6 namespace=tekton-results operation=CREATE policy=restrict-docker-io-images resource=tekton-results/Pod/tekton-results-watcher-55667bb668-756b6 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2df5bca2-ce95-4dcb-aa9e-cecd766ea990 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=744a5e4a-44d5-4cab-bcf1-e7cdc8ca4d61"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"e4d3c968-a7e1-4798-a885-212e427428e8","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-03T14:17:22Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:17:22 http: TLS handshake error from 10.130.0.2:47724: EOF logger=webhooks/server v=0 2026-07-03T14:17:22Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:17:22 http: TLS handshake error from 10.129.0.2:46210: EOF logger=webhooks/server v=0 2026-07-03T14:17:22Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:17:22 http: TLS handshake error from 10.130.0.2:47750: EOF logger=webhooks/server v=0 2026-07-03T14:17:22Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:17:22 http: TLS handshake error from 10.130.0.2:47746: EOF logger=webhooks/server v=0 2026-07-03T14:18:09Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:18:09 http: TLS handshake error from 10.128.0.2:57598: EOF logger=webhooks/server v=0 2026-07-03T14:18:09Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:18:09 http: TLS handshake error from 10.130.0.2:42694: EOF logger=webhooks/server v=0 2026-07-03T14:18:20Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="apps/v1, Kind=StatefulSet" gvr="apps/v1, Resource=statefulsets" kind=StatefulSet logger=webhooks/resource/validate name=affinity-assistant-df20caf2f7 namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/StatefulSet/affinity-assistant-df20caf2f7 resource.gvk="apps/v1, Kind=StatefulSet" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=7e171e53-a41d-4d57-b275-323e7ed38937 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:18:20Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:statefulset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=affinity-assistant-df20caf2f7-0 namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/affinity-assistant-df20caf2f7-0 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c400eb06-d1f7-458a-8142-f414410a9970 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=efc07d9a-420a-444b-a689-e74bcec82b48"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"61081088-df98-4970-8171-5160775198de","username":"system:serviceaccount:kube-system:statefulset-controller"} v=2 2026-07-03T14:18:20Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-bdjalwolqz-init-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/buildah-demo-bdjalwolqz-init-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=de613424-1cee-4c1d-9eba-734af30ad45e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:18:28Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-g7pg7 namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-g7pg7 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=66b466ab-0b9b-4cfc-8262-e67a3fdbe51b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=744a5e4a-44d5-4cab-bcf1-e7cdc8ca4d61"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"e4d3c968-a7e1-4798-a885-212e427428e8","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-03T14:18:37Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-bdjalwolqz-clone-repository-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/buildah-demo-bdjalwolqz-clone-repository-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e6d98b1d-a390-41a0-9784-97a156966bc8 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:18:59Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-sgn7j namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-sgn7j resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=591da327-ef11-452f-807d-2a78a3802c0a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=744a5e4a-44d5-4cab-bcf1-e7cdc8ca4d61"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"e4d3c968-a7e1-4798-a885-212e427428e8","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-03T14:19:04Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=buildah-demo-bdjalwolqz-prefetch-dependencies-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=08f1bc4d-44f2-492f-9d0b-dfaf3d9fb1a4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:19:04Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=buildah-demo-bdjalwolqz-prefetch-dependencies-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=9e176813-e10a-4deb-9253-f8791003ccf7 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:19:04Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-bdjalwolqz-prefetch-dependencies-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/buildah-demo-bdjalwolqz-prefetch-dependencies-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6515cb27-8727-49f5-a142-ebd0e886c7e3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:19:22Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-bdjalwolqz-build-container-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/buildah-demo-bdjalwolqz-build-container-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0c524fe0-ad51-4906-83f9-54f8fef7ed2c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718140 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718140 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6ad81952-3e47-4842-9695-8051ba74ecc3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=81d2586a-c6d6-4b3f-b9ed-9eae6b16c64a"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718140 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29718140 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=093528df-1b25-40b9-820c-11bc19f473d4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=81d2586a-c6d6-4b3f-b9ed-9eae6b16c64a"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:20:00Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:20:00 http: TLS handshake error from 10.130.0.2:56142: EOF logger=webhooks/server v=0 2026-07-03T14:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718140-xsvjl namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718140-xsvjl resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2d46eb2b-58f2-42bd-92fb-224d4356aba5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64707764-661a-40aa-8127-6dfd4ef350e6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718140-bbz5g namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29718140-bbz5g resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e87d75aa-9a6a-4f3f-bcfe-a90be0f57934 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64707764-661a-40aa-8127-6dfd4ef350e6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:21:14Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-czlnt namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-czlnt resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=13c930c9-05b6-4b44-92d0-727e63f717ce user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=744a5e4a-44d5-4cab-bcf1-e7cdc8ca4d61"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"e4d3c968-a7e1-4798-a885-212e427428e8","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-03T14:21:15Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-bdjalwolqz-build-image-index-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/buildah-demo-bdjalwolqz-build-image-index-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=be9c5eb6-257b-4549-916d-d87a8d287b1d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:22:06Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-bdjalwolqz-apply-tags-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/buildah-demo-bdjalwolqz-apply-tags-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4e15b2d5-5c67-4f81-a08d-98505771af31 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:22:06Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-bdjalwolqz-push-dockerfile-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/buildah-demo-bdjalwolqz-push-dockerfile-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1ad863a6-1fe0-4bb4-990d-027b736974e9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:22:06Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:22:06 http: TLS handshake error from 10.128.0.2:49946: EOF logger=webhooks/server v=0 2026-07-03T14:22:21Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-0ee92b84510a2e2bd81a58a216702844-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=99705b0b-d7eb-4b34-a36c-d0194df73eaf user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:22:21Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-0ee92b84510a2e2bd81a58a216702844-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=4bccbefd-6575-427e-8aa5-d951e5eaf8b2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:22:21Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-0ee92b84510a2e2bd81a58a216702844-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/verify-enterprise-contract-0ee92b84510a2e2bd81a58a216702844-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=68a1799a-1928-4cf0-9f9d-f44ccf86f1de user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:22:43Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-9680473ec2b0e9f5db31dbc61d696206-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=6ac4de58-d1be-4a2a-b7d0-07b97f4905ff user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:22:43Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-9680473ec2b0e9f5db31dbc61d696206-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=04d9b3ce-f2d6-4570-9e53-53840348c191 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:22:43Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-9680473ec2b0e9f5db31dbc61d696206-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/verify-enterprise-contract-9680473ec2b0e9f5db31dbc61d696206-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=67c0d8eb-70ef-4d41-9058-5b49f5853bab user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:22:44Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-djgnd namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-djgnd resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ea56e3b6-9b6d-4a49-8428-dc496a78258f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=744a5e4a-44d5-4cab-bcf1-e7cdc8ca4d61"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"e4d3c968-a7e1-4798-a885-212e427428e8","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-03T14:22:57Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-5339ddb69febdb1bccde5e7e4887a95a-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=53fbe4ef-d2cd-4e5b-8772-5e6760879d8c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:22:57Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-5339ddb69febdb1bccde5e7e4887a95a-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=e04ab3ec-b679-4b5b-b800-99595845c864 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:22:57Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-5339ddb69febdb1bccde5e7e4887a95a-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/verify-enterprise-contract-5339ddb69febdb1bccde5e7e4887a95a-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=12fe6f59-10de-474b-99ac-e4033e79b4e4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:23:17Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-5a2b944b42ece2f324bedbf0ea0e5598-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=5936c597-dd1a-4690-a183-011e740e7fd9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:23:17Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-5a2b944b42ece2f324bedbf0ea0e5598-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=1c47d440-5596-4f6f-8ef8-d184ceaa06db user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:23:17Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-5a2b944b42ece2f324bedbf0ea0e5598-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/verify-enterprise-contract-5a2b944b42ece2f324bedbf0ea0e5598-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6aa15ca3-9e2f-433f-8c24-ec1ea92b76e7 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:23:29Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-6d9afc4faa1c797c3f67e0e2d2171744-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=60ae5494-785b-416d-9dd5-bf57dab6d9aa user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:23:30Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-6d9afc4faa1c797c3f67e0e2d2171744-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=57260f0f-584c-4456-b741-3d986ba1ee7f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:23:30Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-6d9afc4faa1c797c3f67e0e2d2171744-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/verify-enterprise-contract-6d9afc4faa1c797c3f67e0e2d2171744-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4bc3eb7b-bb17-42ad-8072-5ed4f1a1c0e6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:23:43Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-bc4a76cd53ddc76769fc9f6d5451fbaf-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=09198b3e-27a2-4074-a7e1-b1461b014b78 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:23:43Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-bc4a76cd53ddc76769fc9f6d5451fbaf-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=9d122ccc-c77b-4d6a-9638-c01050efdd00 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:23:43Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-bc4a76cd53ddc76769fc9f6d5451fbaf-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/verify-enterprise-contract-bc4a76cd53ddc76769fc9f6d5451fbaf-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=05391129-4490-4393-8502-e88afaa2c737 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:24:01Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-e8e036971bb692e173b91a81d9962d45-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=cbfb4603-c9eb-4759-8636-04f01e512510 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:24:01Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-e8e036971bb692e173b91a81d9962d45-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=37a5852e-3972-4f8d-b4f8-097ebeb1fcbd user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:24:01Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-e8e036971bb692e173b91a81d9962d45-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/verify-enterprise-contract-e8e036971bb692e173b91a81d9962d45-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0441c3a7-c51d-47c0-b40e-3ed7dff19e21 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a096b944-60e0-4dc9-8622-7fb60cdcddbe"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["352017f2-1743-40ec-8343-c003a1572bca"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:24:33Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-d34237d941ade5ffa0ec08c3a5a064ff-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=e333d9b8-1116-42ff-91b2-b9d1c47a0ac6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:24:33Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-d34237d941ade5ffa0ec08c3a5a064ff-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=44fb94ae-f79d-4c3f-8022-99ec0cb6acdd user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:24:33Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-d34237d941ade5ffa0ec08c3a5a064ff-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/verify-enterprise-contract-d34237d941ade5ffa0ec08c3a5a064ff-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6c3af738-54f5-46df-8eef-0a4ff289078b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:24:47Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-d491d221acdb38e991f7b978c6ecedc7-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=2a7fb9e3-df77-4687-b35e-ba3839352c08 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:24:47Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-d491d221acdb38e991f7b978c6ecedc7-pod namespace=chains-e2e-epwq operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=91eeb86a-b1b4-49fc-8665-7bb7df3986ba user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:24:47Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-d491d221acdb38e991f7b978c6ecedc7-pod namespace=chains-e2e-epwq operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-epwq/Pod/verify-enterprise-contract-d491d221acdb38e991f7b978c6ecedc7-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5e0e1921-8880-473d-a045-438936354697 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4addb036-789e-4d20-9c45-2d20356e0b03"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["fd982bde-1672-481d-a623-0c3a2476d8d4"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"27f046ab-3d7d-4934-b1cd-371f2d3c5e71","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-07-03T14:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718145 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718145 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f2f70268-6a54-451e-8949-4512382fc308 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=81d2586a-c6d6-4b3f-b9ed-9eae6b16c64a"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718145-vk8kg namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718145-vk8kg resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6527f798-4289-44ba-bd88-12606ae59d16 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64707764-661a-40aa-8127-6dfd4ef350e6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:25:02Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:02 http: TLS handshake error from 10.129.0.2:51136: EOF logger=webhooks/server v=0 2026-07-03T14:25:02Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:02 http: TLS handshake error from 10.128.0.2:38398: EOF logger=webhooks/server v=0 2026-07-03T14:25:02Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:02 http: TLS handshake error from 10.129.0.2:51148: EOF logger=webhooks/server v=0 2026-07-03T14:25:02Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:02 http: TLS handshake error from 10.130.0.2:35378: EOF logger=webhooks/server v=0 2026-07-03T14:25:02Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:02 http: TLS handshake error from 10.129.0.2:51170: EOF logger=webhooks/server v=0 2026-07-03T14:25:02Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:02 http: TLS handshake error from 10.130.0.2:35384: EOF logger=webhooks/server v=0 2026-07-03T14:25:02Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:02 http: TLS handshake error from 10.129.0.2:51162: EOF logger=webhooks/server v=0 2026-07-03T14:25:02Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:02 http: TLS handshake error from 10.128.0.2:38406: EOF logger=webhooks/server v=0 2026-07-03T14:25:02Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:02 http: TLS handshake error from 10.129.0.2:51176: EOF logger=webhooks/server v=0 2026-07-03T14:25:03Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:03 http: TLS handshake error from 10.130.0.2:35408: EOF logger=webhooks/server v=0 2026-07-03T14:25:03Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:03 http: TLS handshake error from 10.129.0.2:51190: EOF logger=webhooks/server v=0 2026-07-03T14:25:06Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:06 http: TLS handshake error from 10.129.0.2:58038: EOF logger=webhooks/server v=0 2026-07-03T14:25:06Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:06 http: TLS handshake error from 10.128.0.2:38414: EOF logger=webhooks/server v=0 2026-07-03T14:25:06Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:06 http: TLS handshake error from 10.129.0.2:58066: EOF logger=webhooks/server v=0 2026-07-03T14:25:06Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:06 http: TLS handshake error from 10.130.0.2:49320: EOF logger=webhooks/server v=0 2026-07-03T14:25:07Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:07 http: TLS handshake error from 10.128.0.2:38428: EOF logger=webhooks/server v=0 2026-07-03T14:25:07Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:07 http: TLS handshake error from 10.129.0.2:58078: EOF logger=webhooks/server v=0 2026-07-03T14:25:08Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:08 http: TLS handshake error from 10.128.0.2:38438: EOF logger=webhooks/server v=0 2026-07-03T14:25:08Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:08 http: TLS handshake error from 10.130.0.2:49334: EOF logger=webhooks/server v=0 2026-07-03T14:25:08Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:08 http: TLS handshake error from 10.128.0.2:38434: EOF logger=webhooks/server v=0 2026-07-03T14:25:08Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:08 http: TLS handshake error from 10.128.0.2:38442: EOF logger=webhooks/server v=0 2026-07-03T14:25:09Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:25:09 http: TLS handshake error from 10.129.0.2:58090: EOF logger=webhooks/server v=0 2026-07-03T14:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718150 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29718150 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6cfeb35c-6455-413c-b2fc-cdcdca8fba3f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=81d2586a-c6d6-4b3f-b9ed-9eae6b16c64a"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718150 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718150 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=68932d28-5945-44c4-8b24-75a9c2f0d23e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=81d2586a-c6d6-4b3f-b9ed-9eae6b16c64a"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718150-b8lph namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29718150-b8lph resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ec292965-c3d9-4137-a04e-7d7b71f98b5f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64707764-661a-40aa-8127-6dfd4ef350e6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718150-fvshz namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718150-fvshz resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c47baae5-468e-4589-8b46-bc0080715fd2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64707764-661a-40aa-8127-6dfd4ef350e6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718155 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718155 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e271c70d-a6d5-45f5-8112-8cb1d40f194e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=81d2586a-c6d6-4b3f-b9ed-9eae6b16c64a"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718155-9b5ll namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718155-9b5ll resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ebb2d23c-d127-4da0-adab-63fcbfed067c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64707764-661a-40aa-8127-6dfd4ef350e6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718160 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29718160 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=695e4d75-9904-422b-bafb-764e7c916294 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=81d2586a-c6d6-4b3f-b9ed-9eae6b16c64a"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718160 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718160 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=afb75709-0d1d-45d8-9283-c5a700251d65 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=81d2586a-c6d6-4b3f-b9ed-9eae6b16c64a"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718160-wbr9d namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29718160-wbr9d resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=344bed72-7043-47c5-b374-5f3749603cfb user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64707764-661a-40aa-8127-6dfd4ef350e6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718160-rgk27 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718160-rgk27 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=19097c91-ee36-482c-9623-5d83748b5652 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=64707764-661a-40aa-8127-6dfd4ef350e6"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:40:28Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-k2gzb namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-k2gzb resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a29bcce4-d45e-469e-8818-d816e6453995 user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-07-03T14:40:29Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:40:29 http: TLS handshake error from 10.128.0.2:43438: EOF logger=webhooks/server v=0 2026-07-03T14:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718165 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718165 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9df683fd-f87a-4a43-9b10-3240412f0f26 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=81d2586a-c6d6-4b3f-b9ed-9eae6b16c64a"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718165-xhm8t namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718165-xhm8t resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=62188900-8ffd-4c01-a65e-9068d0187ec0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718170 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718170 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=3cd7171d-3c68-4f7a-9796-8322ab262ffa user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718170 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29718170 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1afc0bfa-260d-4821-b3c4-11b67d7cf9c1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:50:00Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 14:50:00 http: TLS handshake error from 10.128.0.2:55284: EOF logger=webhooks/server v=0 2026-07-03T14:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718170-l949z namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718170-l949z resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=03c4eb2c-07c9-4184-8085-9c0c75950b09 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718170-29jzz namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29718170-29jzz resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8b44d2db-bc60-4714-8463-0ee9ef040b14 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T14:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718175 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718175 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=46bb4149-3f0e-4222-b51d-bca1c97110fc user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T14:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718175-jtvcd namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718175-jtvcd resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=eba1675f-b9e0-4550-a747-33e290c3be6a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=namespace-claim-cleaner-29718180 namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Job/namespace-claim-cleaner-29718180 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8691cdff-e1c5-4d3b-9461-3e961a485ae2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718180 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718180 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b156f976-9877-406c-b998-7b59b97af7e0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 15:00:00 http: TLS handshake error from 10.130.0.2:58510: EOF logger=webhooks/server v=0 2026-07-03T15:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718180 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29718180 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=653e062b-e7ed-4ff7-9cde-905c9dbeca36 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=namespace-claim-cleaner-29718180-hts6k namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Pod/namespace-claim-cleaner-29718180-hts6k resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d57d5679-c187-4271-b693-3c1cf25385b4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718180-4mhd4 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29718180-4mhd4 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=7b155811-ceb7-43cd-abb6-b17ba653cb47 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718180-wj48s namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718180-wj48s resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=29ad5a88-e4ca-44a8-874d-c5a7913287d2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718185 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718185 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=cffca539-654d-4382-8af6-d0aaee229fe6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718185-d9kj9 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718185-d9kj9 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b18cddf0-dee5-456c-a4a2-a76cfd9f5c9e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:09:17Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=oauth-secret-generator namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Job/oauth-secret-generator resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=09304abe-9fa8-40df-92e8-780a92d3af95 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=bd52d308-1eee-4655-bdcc-5d59e3ba3ffe"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["4ef5b9d4-c55e-4b27-a6e5-31080f3efd5d"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"96a5b0d3-e238-401b-b4da-7accae891fe8","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-07-03T15:09:17Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=oauth-secret-generator-g726q namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/oauth-secret-generator-g726q resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ca606dab-8503-4996-b1e7-570353151b43 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:09:34Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=image-rbac-proxy-6447dfcf85-fz5mr namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/image-rbac-proxy-6447dfcf85-fz5mr resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=3f0e3c25-8a14-4701-8046-9af0382a7983 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a6dc5b1e-3efc-4107-a6d3-b68f6dd2d019"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"e4d3c968-a7e1-4798-a885-212e427428e8","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-03T15:09:34Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=dex-58cd7f8bf8-kxgrn namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/dex-58cd7f8bf8-kxgrn resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4ff17a72-bfc5-41e6-82aa-95d7a9efc88f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=a6dc5b1e-3efc-4107-a6d3-b68f6dd2d019"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"e4d3c968-a7e1-4798-a885-212e427428e8","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-07-03T15:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718190 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718190 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=acb59dcf-5c1a-4048-b645-7b1791897ec8 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718190 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29718190 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=467c5e13-8a09-4053-956b-81700f3dc0ff user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:10:00Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 15:10:00 http: TLS handshake error from 10.130.0.2:49968: EOF logger=webhooks/server v=0 2026-07-03T15:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718190-62ggw namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718190-62ggw resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=466b715f-e5e9-4969-93ec-e775f76c3685 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718190-7m4ln namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29718190-7m4ln resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=97a89192-c6f1-44ea-9d1f-53e95e15d495 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:10:28Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-m8tt6 namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-m8tt6 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e569ef79-a1f9-4a3f-aaad-e3bf7a64d194 user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-07-03T15:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718195 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718195 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=be99952a-6283-424c-8254-c600d8c4001d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718195-hbfzh namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718195-hbfzh resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2227bb80-2892-4bdc-9520-f36e177d353f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718200 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718200 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6d07bedf-5a65-420d-9ce8-e5fccfc00e59 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718200 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29718200 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a2be5cc1-3b97-44be-bbcd-1c1c4a3df86f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:20:00Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 15:20:00 http: TLS handshake error from 10.128.0.2:39626: EOF logger=webhooks/server v=0 2026-07-03T15:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718200-b8jnt namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718200-b8jnt resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=63202aae-3841-4104-a103-93c6621fce86 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718200-dhh85 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29718200-dhh85 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=af95a4f8-06f5-453a-88ed-9e78be2e2b70 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718205 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718205 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c68b1bbe-ad51-4c9f-a2ca-3dd208e2b050 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718205-xxx96 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718205-xxx96 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=57b081d3-cbf7-4ca8-85fc-c0367e26822e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718210 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718210 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=3e60f698-2685-49ca-84a9-5073c8a0d6dc user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718210 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29718210 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1d518296-ae5e-45f4-ae04-b4783f1c8ce2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718210-4xl9g namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718210-4xl9g resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=598de730-b8f3-4707-aa80-ed296cb80630 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718210-xkl5p namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29718210-xkl5p resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d7426e0d-0875-4ca4-8c13-eb0cca1a4f4b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=c2e2d090-4f65-4bf2-a009-25ec7734cc15"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718215 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718215 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=90dff0ef-0171-42a7-a15c-6f79e75ce05e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4082cd04-7125-4db8-8b5c-8c063207ac2c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718215-dfbtx namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718215-dfbtx resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=21766d2e-ce38-4455-8feb-15706dda6d87 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=ded8a710-ba80-45cf-beb9-57ac5c661feb"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718220 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29718220 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=80df1afa-03ef-478e-8a02-3009a5e3ef40 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4ea85aed-54fc-4a96-a44a-1acf179d0b46"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718220 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718220 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1616369c-9268-4738-bc68-08d563e2da21 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4ea85aed-54fc-4a96-a44a-1acf179d0b46"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:40:00Z INF kyverno/pkg/logging/log.go:180 > 2026/07/03 15:40:00 http: TLS handshake error from 10.130.0.2:58424: EOF logger=webhooks/server v=0 2026-07-03T15:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29718220-87vxz namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29718220-87vxz resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=887f3257-4ddd-4518-9c11-6ae97ced481b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=ded8a710-ba80-45cf-beb9-57ac5c661feb"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718220-f29vr namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718220-f29vr resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=069dbf5a-30c2-4313-9b88-9070bfd81f73 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=ded8a710-ba80-45cf-beb9-57ac5c661feb"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-07-03T15:40:28Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-xcsdq namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-xcsdq resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d8d8bd61-670c-426d-8282-1eb1ee7b72c4 user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-07-03T15:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29718225 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29718225 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c1c66392-cc53-4264-a5c6-fe8193f6efde user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4ea85aed-54fc-4a96-a44a-1acf179d0b46"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"da2b23df-0368-492c-9db5-725c55c04792","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-07-03T15:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29718225-6rhg7 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29718225-6rhg7 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=138f9045-73d8-48de-b96c-6d9c03e47308 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=ded8a710-ba80-45cf-beb9-57ac5c661feb"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"430ccdce-b2cd-4859-90d1-08c66d36d50c","username":"system:serviceaccount:kube-system:job-controller"} v=2