2026-06-29T14:36:35Z TRC kyverno/pkg/version/version.go:49 > version hash=--- logger=setup/version v=2 version=1.25.8 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > add_dir_header=false logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > admissionReports=false logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > allowInsecureRegistry=false logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > alsologtostderr=false logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > autoDeleteWebhooks=false logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > autoUpdateWebhooks=true logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > backgroundServiceAccountName=system:serviceaccount:konflux-kyverno:kyverno-background-controller logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > caSecretName=konflux-kyverno-svc.konflux-kyverno.svc.kyverno-tls-ca logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > cleanupServerPort=9443 logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > clientRateLimitBurst=200 logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > clientRateLimitQPS=100 logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > controllerRuntimeMetricsAddress=:8080 logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > crdWatcher=false logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > disableLogColor=false logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > disableMetrics=false logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > dumpPatches= logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > dumpPayload=false logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > enableConfigMapCaching=true logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > enableDeferredLoading= logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > enablePolicyException=false logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > enableReporting= logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > enableTracing=false logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > enableTuf=false logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > eventsRateLimitBurst=2000 logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > eventsRateLimitQPS=1000 logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > exceptionNamespace= logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > forceFailurePolicyIgnore= logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > generateMutatingAdmissionPolicy= logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > generateValidatingAdmissionPolicy= logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > imagePullSecrets= logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheEnabled=true logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheMaxSize=1000 logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheTTLDuration=1h0m0s logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > kubeconfig= logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > leaderElectionRetryPeriod=26s logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > log_backtrace_at=:0 logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > log_dir= logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > log_file= logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > log_file_max_size=1800 logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag loggingFormat=text v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag loggingtsFormat=default v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag logtostderr=true v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAPICallResponseLength=2000000 v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAdmissionReports=1000 v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAuditCapacity=1000 v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAuditWorkers=8 v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxQueuedEvents=1000 v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag metricsPort=8000 v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag omitEvents=PolicyApplied,PolicySkipped v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag one_output=false v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag otelCollector=opentelemetrycollector.kyverno.svc.cluster.local v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag otelConfig=prometheus v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profile=false v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profileAddress= v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profilePort=6060 v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag protectManagedResources= v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag registryCredentialHelpers=default,google,amazon,azure,github v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag renewBefore=360h0m0s v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag reportsServiceAccountName= v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag resyncPeriod=15m0s v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag serverIP= v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag servicePort=443 v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag skip_headers=false v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag skip_log_headers=false v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag stderrthreshold=2 v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tlsSecretName=konflux-kyverno-svc.konflux-kyverno.svc.kyverno-tls-pair v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingAddress= v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingCreds= v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingPort=4317 v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag transportCreds= v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufMirror=https://tuf-repo-cdn.sigstore.dev v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufRoot= v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufRootRaw= v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 vmodule= 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookRegistrationTimeout=2m0s 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookServerPort=9443 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookTimeout=10 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/maxprocs.go:12 > setup maxprocs... logger=setup/maxprocs v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/signal.go:16 > setup signals... logger=setup/signals v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/kube-client qps=100 v=2 2026-06-29T14:36:35Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=InformerResourceVersion logger=klog v=1 2026-06-29T14:36:35Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=true feature=InOrderInformers logger=klog v=1 2026-06-29T14:36:35Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=WatchListClient logger=klog v=1 2026-06-29T14:36:35Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=ClientsAllowCBOR logger=klog v=1 2026-06-29T14:36:35Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=ClientsPreferCBOR logger=klog v=1 2026-06-29T14:36:35Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-06-29T14:36:35Z TRC kyverno/cmd/internal/metrics.go:18 > setup metrics... collector=opentelemetrycollector.kyverno.svc.cluster.local creds= logger=setup/metrics otel=prometheus port=8000 v=2 2026-06-29T14:36:35Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:417 > defaultRegistry configured defaultRegistry=docker.io logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:433 > enableDefaultRegistryMutation configured enableDefaultRegistryMutation=true logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:442 > excludedGroups configured excludeGroups=["system:nodes"] includeGroups=[] logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:447 > excludeUsernames not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:455 > excludeRoles not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:463 > excludeClusterRoles not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:479 > generateSuccessEvents configured generateSuccessEvents=false logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:493 > webhooks configured logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 webhooks="{\"namespaceSelector\":{\"matchExpressions\":[{\"key\":\"kubernetes.io/metadata.name\",\"operator\":\"NotIn\",\"values\":[\"kube-system\"]},{\"key\":\"kubernetes.io/metadata.name\",\"operator\":\"NotIn\",\"values\":[\"konflux-kyverno\"]}],\"matchLabels\":null}}" 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:507 > webhookAnnotations configured logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 webhookAnnotations="{\"admissions.enforcer/disabled\":\"true\"}" 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:513 > webhookLabels not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:527 > matchConditions not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:548 > enableDefaultRegistryMutation configured enableDefaultRegistryMutation=true logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T14:36:36Z TRC kyverno/pkg/config/config.go:563 > maxContextSize not set, using default default=2097152 logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/registry.go:18 > setup registry client... insecure=false logger=setup/registry-client secrets= v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/imageverifycache.go:10 > setup image verify cache... enabled=true logger=setup/image-verify-cache maxsize=1000 ttl=1h0m0s v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/kube-client qps=100 v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/client.go:60 > create kyverno client... burst=200 kubeconfig= logger=setup/kyverno-client qps=100 v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/client.go:68 > create dynamic client... burst=200 kubeconfig= logger=setup/dynamic-client qps=100 v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/client.go:84 > create apiserver client... burst=200 kubeconfig= logger=setup/apiserver-client qps=100 v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/client.go:76 > create metadata client... burst=200 kubeconfig= logger=setup/metadata-client qps=100 v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/client.go:92 > create the kyverno dynamic client... burst=200 kubeconfig= logger=setup/d-client qps=100 v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/client.go:100 > create the events client... burst=200 kubeconfig= logger=setup/events-client qps=100 v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/events-client/kube-client qps=100 v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/reporting.go:13 > setting up reporting... enableReporting= generate=false imageVerify=false logger=setup/setup-reporting mutate=false mutateExisiting=false v=2 validate=false 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Deployment v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/engine.go:65 > setup exception selector... enablePolicyException=false exceptionNamespace= logger=setup/exception-selector v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/engine.go:94 > setup config map resolver... enableConfigMapCaching=true logger=setup/configmap-resolver v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/engine.go:46 > setup engine... logger=setup/engine v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Policy v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2alpha1.GlobalContextEntry v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Deployment v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterPolicy v=2 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/metrics/server/server.go:208 > Starting metrics server logger=controller-runtime/metrics v=0 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/metrics/server/server.go:247 > Serving metrics server bindAddress=:8080 logger=controller-runtime/metrics secure=false v=0 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy source="kind source: *v1alpha1.ValidatingPolicy" v=0 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy source="kind source: *v1alpha1.MutatingPolicy" v=0 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy source="kind source: *v1alpha1.ImageValidatingPolicy" v=0 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2.UpdateRequest v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.PolicyException v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.GeneratingPolicy v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Namespace v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterRoleBinding v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ValidatingPolicy v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.MutatingPolicy v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ImageValidatingPolicy v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.RoleBinding v=2 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/leaderelection/leaderelection.go:257 > attempting to acquire leader lease konflux-kyverno/kyverno... logger=klog v=0 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup name=kyverno-events v=2 workers=3 2026-06-29T14:36:36Z TRC kyverno/pkg/event/controller.go:106 > start logger=EventGenerator v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/controllers name=policycache-controller v=2 workers=3 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup name=global-context v=2 workers=1 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/leaderelection/leaderelection.go:271 > successfully acquired lease konflux-kyverno/kyverno logger=klog v=0 2026-06-29T14:36:36Z TRC kyverno/pkg/leaderelection/leaderelection.go:83 > started leading id=kyverno-admission-controller-5cbb799dc8-m95wn logger=setup/leader-election v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.PolicyException v=2 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy v=0 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy v=0 worker count=1 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy v=0 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy v=0 worker count=1 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy v=0 2026-06-29T14:36:36Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy v=0 worker count=1 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterPolicy v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.GeneratingPolicy v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Policy v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ImageValidatingPolicy v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Lease v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2.PolicyException v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.MutatingPolicy v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ValidatingPolicy v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingAdmissionPolicyBinding v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingAdmissionPolicy v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.MutatingWebhookConfiguration v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingWebhookConfiguration v=2 2026-06-29T14:36:36Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterRole v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=admissionpolicy-generator v=2 workers=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=status-controller v=2 workers=3 2026-06-29T14:36:36Z TRC kyverno/pkg/utils/controller/run.go:58 > starting ... logger=admissionpolicy-generator v=2 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=celexception-webhook-controller v=2 workers=1 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=exception-webhook-controller v=2 workers=1 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=certmanager-controller v=2 workers=1 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=global-context-webhook-controller v=2 workers=1 2026-06-29T14:36:36Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=webhook-controller v=2 workers=2 2026-06-29T14:36:39Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:36:39 http: TLS handshake error from 10.129.0.2:39686: secret "konflux-kyverno-svc.konflux-kyverno.svc.kyverno-tls-pair" not found logger=webhooks/server v=0 2026-06-29T14:39:33Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:39:33 http: TLS handshake error from 10.129.0.2:36886: EOF logger=webhooks/server v=0 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpingress type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpingress uid=4eca9d3e-bfda-4cd0-8962-ac294fcc33e8 v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-samenamespace type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-samenamespace uid=7aac14fa-1a7a-429e-b04a-0922de2b7875 v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-olm uid=24b3eef0-84d9-4217-a5ca-472f31fecea9 v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-olm type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpmonitoring uid=7dd64864-1e2a-4ee7-91ef-959cf02eb2a7 v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpmonitoring type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=init-ns-kubearchiveconfig uid=5911af34-0e06-4d1f-af1d-c74eff40487e v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=init-ns-kubearchiveconfig type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpconsole uid=077cc81e-2705-4fc0-a779-adf5e49b2e5f v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpconsole type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-rbcm uid=691c4025-4251-4621-9f63-ec9118930d48 v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-rbcm type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=integration-init-ns-integration uid=fc42ad05-3837-4b9e-a26c-5d8e68cebc84 v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=integration-init-ns-integration type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-generate-konflux-viewer-access uid=059f2500-3608-447e-8398-3ed26371ead1 v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-generate-konflux-viewer-access type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-validate-restrict-binding-sysauth-releng type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-validate-restrict-binding-sysauth-releng uid=ae20520a-d989-401d-ba76-7df0f3ad0a1f v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-validate-restrict-binding-system-authenticated type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-validate-restrict-binding-system-authenticated uid=69ced11b-b510-4898-8af9-96293c17f6e4 v=2 2026-06-29T14:39:33Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"konflux-rbac-validate-restrict-binding-sysauth-releng\": the object has been modified; please apply your changes to the latest version and try again" konflux-rbac-validate-restrict-binding-sysauth-releng=status 2026-06-29T14:39:33Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"konflux-rbac-validate-restrict-binding-system-authenticated\": the object has been modified; please apply your changes to the latest version and try again" konflux-rbac-validate-restrict-binding-system-authenticated=status 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=restrict-binding-system-groups type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=restrict-binding-system-groups uid=b830ed1c-688d-49cc-85de-4cf0b577f8b3 v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=restrict-docker-io-images uid=40fcbfd4-1c57-4124-847f-580173561c72 v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=restrict-docker-io-images type=ClusterPolicy v=2 2026-06-29T14:39:33Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"restrict-binding-system-groups\": the object has been modified; please apply your changes to the latest version and try again" restrict-binding-system-groups=status 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=tekton-taskrun-resource-policy type=ClusterPolicy v=2 2026-06-29T14:39:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=tekton-taskrun-resource-policy uid=83ad53e3-581d-4569-926a-177d8c59e434 v=2 2026-06-29T14:39:33Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"restrict-docker-io-images\": the object has been modified; please apply your changes to the latest version and try again" restrict-docker-io-images=status 2026-06-29T14:39:45Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=bootstrap-tenant-namespace-queue type=ClusterPolicy v=2 2026-06-29T14:39:45Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=bootstrap-tenant-namespace-queue uid=e2b15ae4-4704-40fc-93fd-722a9d0c7e4b v=2 2026-06-29T14:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712400 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712400 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9be4b059-3f5f-409b-90b2-cc3183dbf2f2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48b73478-57a0-40b9-950d-9a61ca4cda6c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T14:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712400 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712400 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e3654cb5-c14b-46ee-8c04-5018dbc50a53 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48b73478-57a0-40b9-950d-9a61ca4cda6c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T14:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712400-2rwwj namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712400-2rwwj resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ed9ef611-08b7-4a95-b917-b29ac450ee3e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1d1ae15e-54ff-432e-ba3c-4fbf32be4d9b"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T14:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712400-xsrzp namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712400-xsrzp resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=33c04648-9bb3-4c62-a536-75cf81d28964 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1d1ae15e-54ff-432e-ba3c-4fbf32be4d9b"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T14:40:31Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:40:31 http: TLS handshake error from 10.128.0.2:55542: EOF logger=webhooks/server v=0 2026-06-29T14:40:31Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:40:31 http: TLS handshake error from 10.130.0.2:43706: EOF logger=webhooks/server v=0 2026-06-29T14:40:51Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=tekton-results-watcher namespace=tekton-results operation=CREATE policy=restrict-docker-io-images resource=tekton-results/Deployment/tekton-results-watcher resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=ed551f6a-ea61-4f0a-a33c-5df2a9b74207 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2b2ef811-526a-4a45-99fb-e4a1f3baeba4"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["d008354e-3f73-4456-a3d8-4591d924acb2"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"3a752342-0a3b-4511-b284-5003ab1d2615","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T14:40:51Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-results-watcher-55667bb668-k69k2 namespace=tekton-results operation=CREATE policy=restrict-docker-io-images resource=tekton-results/Pod/tekton-results-watcher-55667bb668-k69k2 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a9489563-05bc-4c56-9923-35b621251609 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=3a0b691f-3a81-4e8a-8082-4148917936b4"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"0263a760-e641-4477-89e2-9ed4ec753e87","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T14:44:39Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:44:39 http: TLS handshake error from 10.129.0.2:46262: EOF logger=webhooks/server v=0 2026-06-29T14:44:39Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:44:39 http: TLS handshake error from 10.128.0.2:52184: EOF logger=webhooks/server v=0 2026-06-29T14:44:39Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:44:39 http: TLS handshake error from 10.129.0.2:46286: EOF logger=webhooks/server v=0 2026-06-29T14:44:39Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:44:39 http: TLS handshake error from 10.128.0.2:52204: EOF logger=webhooks/server v=0 2026-06-29T14:44:39Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:44:39 http: TLS handshake error from 10.129.0.2:46296: EOF logger=webhooks/server v=0 2026-06-29T14:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712405 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712405 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=104da22f-aaaa-4d84-855c-048b8c366a29 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48b73478-57a0-40b9-950d-9a61ca4cda6c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T14:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712405-g7jqx namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712405-g7jqx resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=346c1183-aa5d-4f6a-9a97-f33daaf1dbf3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1d1ae15e-54ff-432e-ba3c-4fbf32be4d9b"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T14:45:36Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:45:36 http: TLS handshake error from 10.130.0.2:43574: EOF logger=webhooks/server v=0 2026-06-29T14:45:37Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:45:37 http: TLS handshake error from 10.128.0.2:53960: EOF logger=webhooks/server v=0 2026-06-29T14:45:37Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:45:37 http: TLS handshake error from 10.128.0.2:53970: EOF logger=webhooks/server v=0 2026-06-29T14:45:45Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="apps/v1, Kind=StatefulSet" gvr="apps/v1, Resource=statefulsets" kind=StatefulSet logger=webhooks/resource/validate name=affinity-assistant-96faa2e285 namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/StatefulSet/affinity-assistant-96faa2e285 resource.gvk="apps/v1, Kind=StatefulSet" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0258d5cf-95ae-41a8-a7b3-60ba8d61baca user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:45:45Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:statefulset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=affinity-assistant-96faa2e285-0 namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/affinity-assistant-96faa2e285-0 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=408b4ff6-fc38-4996-86f1-68829b55a509 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8671e8e5-b152-499b-9d56-b93b2998ff51"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"f60e26ac-cb1a-4e1b-9fe3-ff3a4b9271d7","username":"system:serviceaccount:kube-system:statefulset-controller"} v=2 2026-06-29T14:45:46Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-dzsjqkcrgh-init-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/buildah-demo-dzsjqkcrgh-init-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0cdecccc-10d0-4f11-a158-92f66c885849 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cf3bbe0c-b512-4572-8115-52697b87c345"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:46:07Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-dzsjqkcrgh-clone-repository-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/buildah-demo-dzsjqkcrgh-clone-repository-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6f771c0c-9e03-456d-a513-40a70bb8e62c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:46:12Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-5z77s namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-5z77s resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ff25b4af-2154-4328-a9db-a20b75b33767 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=3a0b691f-3a81-4e8a-8082-4148917936b4"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"0263a760-e641-4477-89e2-9ed4ec753e87","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T14:46:30Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=buildah-demo-dzsjqkcrgh-prefetch-dependencies-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=d1ea0b44-2076-4fac-baae-16c136a1ca6c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:46:30Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=buildah-demo-dzsjqkcrgh-prefetch-dependencies-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=df775dfe-cee5-48ab-bcb2-fcdfbb9ced29 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:46:30Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-dzsjqkcrgh-prefetch-dependencies-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/buildah-demo-dzsjqkcrgh-prefetch-dependencies-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a8de5d8b-4aaf-4f71-bc7e-cb84d27bfc75 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:46:50Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-dzsjqkcrgh-build-container-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/buildah-demo-dzsjqkcrgh-build-container-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5b1841d7-16e6-46bc-9f44-9ce962e12e5f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:47:12Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-f9g8b namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-f9g8b resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=84430ee1-b5d9-4a5e-9f45-d9ff5294fc65 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=3a0b691f-3a81-4e8a-8082-4148917936b4"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"0263a760-e641-4477-89e2-9ed4ec753e87","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T14:48:12Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-6hcjn namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-6hcjn resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=bd9d1bbb-e10c-40cd-b936-60b5359dc16b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=3a0b691f-3a81-4e8a-8082-4148917936b4"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"0263a760-e641-4477-89e2-9ed4ec753e87","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T14:48:45Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-dzsjqkcrgh-build-image-index-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/buildah-demo-dzsjqkcrgh-build-image-index-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=77f8c150-4cf8-4206-bef2-bced49d0f9d5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cf3bbe0c-b512-4572-8115-52697b87c345"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:49:35Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-dzsjqkcrgh-apply-tags-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/buildah-demo-dzsjqkcrgh-apply-tags-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=745a21f9-38c0-4377-8166-f2fac5987c30 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:49:35Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-dzsjqkcrgh-push-dockerfile-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/buildah-demo-dzsjqkcrgh-push-dockerfile-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1e0e3845-d6be-4da6-aa28-a58e6ce7cfae user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cf3bbe0c-b512-4572-8115-52697b87c345"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712410 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712410 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5b69f315-7cc4-49f9-b1c4-a67925696a29 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48b73478-57a0-40b9-950d-9a61ca4cda6c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T14:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712410 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712410 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=965f8d0a-eb4d-473a-bf84-46b0d614bdae user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48b73478-57a0-40b9-950d-9a61ca4cda6c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T14:50:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:50:00 http: TLS handshake error from 10.130.0.2:47410: EOF logger=webhooks/server v=0 2026-06-29T14:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712410-sjm2w namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712410-sjm2w resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=3ae0279d-2cc7-482a-803b-5471ed57c0bf user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1d1ae15e-54ff-432e-ba3c-4fbf32be4d9b"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T14:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712410-s76d2 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712410-s76d2 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=bc8967cc-f368-48a3-8312-3ab25e342269 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1d1ae15e-54ff-432e-ba3c-4fbf32be4d9b"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T14:50:05Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-0bc88dc1bc5f0068e6812785e223c4e4-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=1f4bf0da-9c50-4465-8a02-a4eacb16840a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cf3bbe0c-b512-4572-8115-52697b87c345"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:50:05Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-0bc88dc1bc5f0068e6812785e223c4e4-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=4887a411-bc2a-45b4-ac70-a749af573ab5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cf3bbe0c-b512-4572-8115-52697b87c345"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:50:05Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-0bc88dc1bc5f0068e6812785e223c4e4-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/verify-enterprise-contract-0bc88dc1bc5f0068e6812785e223c4e4-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=76cc5171-28f2-4d8b-96d3-bda5e9c70b64 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cf3bbe0c-b512-4572-8115-52697b87c345"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:50:31Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-7debc4c5c86d1715cee3fda469ad6965-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=8b63c93f-2203-403d-9d24-974aed1d25ef user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:50:31Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-7debc4c5c86d1715cee3fda469ad6965-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=1e2c0922-e9be-4f78-beca-2a5efa488045 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:50:31Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-7debc4c5c86d1715cee3fda469ad6965-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/verify-enterprise-contract-7debc4c5c86d1715cee3fda469ad6965-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d36273a3-22c0-4a18-82c9-8fee7afa2565 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:50:55Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-35d599107941c278374b8ad541df6502-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=5b334137-e727-4a71-9bbd-3792f5dcd05d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:50:55Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-35d599107941c278374b8ad541df6502-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=3959f27e-a86c-49ad-9d20-9ed35651e1c7 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:50:55Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-35d599107941c278374b8ad541df6502-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/verify-enterprise-contract-35d599107941c278374b8ad541df6502-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f591d603-0111-4ec4-9bdb-24693aa5e7cb user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:51:11Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-6d0c51607013e7f7c2c2e0ddf8112548-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=072958da-717f-4310-a79b-070dbba17b20 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cf3bbe0c-b512-4572-8115-52697b87c345"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:51:11Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-6d0c51607013e7f7c2c2e0ddf8112548-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=935d1e1b-6ad6-464f-8b7f-a2c8d0fe3584 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cf3bbe0c-b512-4572-8115-52697b87c345"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:51:11Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-6d0c51607013e7f7c2c2e0ddf8112548-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/verify-enterprise-contract-6d0c51607013e7f7c2c2e0ddf8112548-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e8f7f899-fc76-4df2-bc93-05b2ddd2ce46 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cf3bbe0c-b512-4572-8115-52697b87c345"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:51:26Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-2ac3ffebe13daa811cb0a6958bccc92e-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=b6375772-7b33-417e-9dc6-5d90e3d1a3ea user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cf3bbe0c-b512-4572-8115-52697b87c345"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:51:27Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-2ac3ffebe13daa811cb0a6958bccc92e-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=9e878f6a-34c2-47e5-8b81-007dac82c226 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cf3bbe0c-b512-4572-8115-52697b87c345"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:51:27Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-2ac3ffebe13daa811cb0a6958bccc92e-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/verify-enterprise-contract-2ac3ffebe13daa811cb0a6958bccc92e-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b14400b1-9114-4272-abaf-365770810788 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=cf3bbe0c-b512-4572-8115-52697b87c345"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:51:44Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-d38e85412e8460a697144a21d0440409-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=9fe8e868-1520-4e4b-9c1e-f4d069e05f34 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:51:44Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-d38e85412e8460a697144a21d0440409-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=660e6506-98ca-4bd8-a7cf-31c18a8745ea user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:51:44Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-d38e85412e8460a697144a21d0440409-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/verify-enterprise-contract-d38e85412e8460a697144a21d0440409-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=566cfffd-d991-4197-9922-b232ebec66c0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:52:05Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-d3ac66120e9c0f3f6f6067f3a41d3de4-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=86c02056-b270-4ac3-a147-8ac288928e59 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:52:05Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-d3ac66120e9c0f3f6f6067f3a41d3de4-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=ea47bf4f-eaaa-45c1-a7f0-ad9721b5f076 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:52:05Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-d3ac66120e9c0f3f6f6067f3a41d3de4-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/verify-enterprise-contract-d3ac66120e9c0f3f6f6067f3a41d3de4-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e528dd36-8a95-4133-9977-bcd68c74135e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:52:46Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-74364b88d7b9376ca34688b003232c8e-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=afce2503-67a4-4a1a-a0ae-be67994d30b2 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:52:46Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-74364b88d7b9376ca34688b003232c8e-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=f3a78c8e-4306-4a0b-9e6b-777f6d1ee926 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:52:46Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-74364b88d7b9376ca34688b003232c8e-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/verify-enterprise-contract-74364b88d7b9376ca34688b003232c8e-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d269e34a-98d6-4ba6-b380-ca67b6be005f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:53:03Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-c2fca85658cf4f7b54e0aa2ba41d86c9-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=89626515-2de7-4923-aee7-ef22dbbcf4b9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:53:03Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-c2fca85658cf4f7b54e0aa2ba41d86c9-pod namespace=chains-e2e-fmfy operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=f292c104-5f09-4cdc-a8f7-d965eedaab08 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:53:03Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-c2fca85658cf4f7b54e0aa2ba41d86c9-pod namespace=chains-e2e-fmfy operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-fmfy/Pod/verify-enterprise-contract-c2fca85658cf4f7b54e0aa2ba41d86c9-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=186a92f0-acde-4183-b78a-30ccc441e04b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dc41f9b4-f9e6-4c7f-b9ee-90521e1118e8"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["c3fd938d-a29d-4438-bae0-cc3b6b6fb537"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T14:53:20Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:53:20 http: TLS handshake error from 10.128.0.2:40814: EOF logger=webhooks/server v=0 2026-06-29T14:53:20Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:53:20 http: TLS handshake error from 10.130.0.2:49722: EOF logger=webhooks/server v=0 2026-06-29T14:53:20Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:53:20 http: TLS handshake error from 10.129.0.2:55154: EOF logger=webhooks/server v=0 2026-06-29T14:53:25Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:53:25 http: TLS handshake error from 10.128.0.2:36058: EOF logger=webhooks/server v=0 2026-06-29T14:53:25Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:53:25 http: TLS handshake error from 10.130.0.2:49738: EOF logger=webhooks/server v=0 2026-06-29T14:53:25Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:53:25 http: TLS handshake error from 10.129.0.2:55164: EOF logger=webhooks/server v=0 2026-06-29T14:53:25Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:53:25 http: TLS handshake error from 10.130.0.2:49754: EOF logger=webhooks/server v=0 2026-06-29T14:53:25Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:53:25 http: TLS handshake error from 10.130.0.2:49764: EOF logger=webhooks/server v=0 2026-06-29T14:53:26Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:53:26 http: TLS handshake error from 10.129.0.2:55188: EOF logger=webhooks/server v=0 2026-06-29T14:53:26Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:53:26 http: TLS handshake error from 10.130.0.2:49766: EOF logger=webhooks/server v=0 2026-06-29T14:53:27Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:53:27 http: TLS handshake error from 10.129.0.2:55194: EOF logger=webhooks/server v=0 2026-06-29T14:53:27Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 14:53:27 http: TLS handshake error from 10.130.0.2:49788: EOF logger=webhooks/server v=0 2026-06-29T14:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712415 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712415 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9de05a0f-28d4-4fb2-b15f-39edeb1f4f58 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48b73478-57a0-40b9-950d-9a61ca4cda6c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T14:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712415-25r54 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712415-25r54 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9fa28310-918b-4933-86a0-c340c822c78c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1d1ae15e-54ff-432e-ba3c-4fbf32be4d9b"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712420 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712420 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f32c0d83-1c9c-4142-b501-0e754cb6b73b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48b73478-57a0-40b9-950d-9a61ca4cda6c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=namespace-claim-cleaner-29712420 namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Job/namespace-claim-cleaner-29712420 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e2aafe3d-0979-4fb1-8a21-8f232d215158 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48b73478-57a0-40b9-950d-9a61ca4cda6c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 15:00:00 http: TLS handshake error from 10.130.0.2:45964: EOF logger=webhooks/server v=0 2026-06-29T15:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712420 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712420 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0508dd65-bd2b-4f01-8e8d-2d25bd65fbf4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48b73478-57a0-40b9-950d-9a61ca4cda6c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712420-26f82 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712420-26f82 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6097b90a-01b2-4bbb-9b2c-0cba9fea5539 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1d1ae15e-54ff-432e-ba3c-4fbf32be4d9b"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=namespace-claim-cleaner-29712420-lftr2 namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Pod/namespace-claim-cleaner-29712420-lftr2 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=07186148-18e3-4ee7-bc26-71e99fbbd68c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1d1ae15e-54ff-432e-ba3c-4fbf32be4d9b"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 15:00:00 http: TLS handshake error from 10.130.0.2:45976: EOF logger=webhooks/server v=0 2026-06-29T15:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712420-gvs7z namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712420-gvs7z resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=06618a8e-b710-4b74-a785-3663570ebc24 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1d1ae15e-54ff-432e-ba3c-4fbf32be4d9b"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:04:28Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-sfwz8 namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-sfwz8 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d5b145eb-cedf-4323-8317-ebface85973d user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-06-29T15:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712425 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712425 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2cb1b4f3-aacd-4ba9-8fe1-676246c6c706 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48b73478-57a0-40b9-950d-9a61ca4cda6c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712425-2sjn8 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712425-2sjn8 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5a667ea8-f3d1-42b1-8583-b76805e2ccda user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=1d1ae15e-54ff-432e-ba3c-4fbf32be4d9b"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712430 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712430 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=03a1a62d-179b-4938-a728-927d510a03f3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48b73478-57a0-40b9-950d-9a61ca4cda6c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712430 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712430 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b6d87f1d-669a-4f73-bbca-ab5b8fbe08b0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48b73478-57a0-40b9-950d-9a61ca4cda6c"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:10:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 15:10:00 http: TLS handshake error from 10.130.0.2:38766: EOF logger=webhooks/server v=0 2026-06-29T15:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712430-jnf4z namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712430-jnf4z resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2f5f4dce-45ab-49a8-b3fb-a0a3e5e8fe77 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712430-6fqfk namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712430-6fqfk resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5a83d289-9fd9-4ca7-82c1-1ddcad5809b8 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712435 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712435 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=45719ede-0f49-4192-887e-3d77d4620441 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712435-fl2hl namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712435-fl2hl resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=bca7d7a9-add0-4e86-9951-78c6dfc86c5f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712440 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712440 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=606cbd3e-e6cd-459e-8fe4-28d261db2950 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712440 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712440 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=57d3086d-1c81-46a3-9e8d-617c78fd6e74 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:20:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 15:20:00 http: TLS handshake error from 10.130.0.2:35926: EOF logger=webhooks/server v=0 2026-06-29T15:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712440-7q5w8 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712440-7q5w8 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c80cb477-e710-4af2-9483-8df2a08d9005 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712440-fvsdn namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712440-fvsdn resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c4a085f2-8238-4e1a-88de-38624e6c477c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712445 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712445 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=37bda2c1-0af1-4062-96d4-9f0993036663 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712445-kh2fx namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712445-kh2fx resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4738088b-e621-4827-84d5-eea9e917295a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712450 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712450 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ab176357-b4e5-49b8-a491-ac8fe5e51e9d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712450 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712450 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d52e289a-210d-42b7-b727-e6f4ea5dad03 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:30:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 15:30:00 http: TLS handshake error from 10.130.0.2:60418: EOF logger=webhooks/server v=0 2026-06-29T15:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712450-jjfc6 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712450-jjfc6 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=17e39267-1577-46d0-a46a-6b39f97d8148 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712450-xw8w8 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712450-xw8w8 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4b0e5542-8b54-4cda-a651-8e51d39b0eda user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:34:17Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=oauth-secret-generator namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Job/oauth-secret-generator resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=be79f4ce-7fcd-4830-8a46-26d4d43626af user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=abacbbe9-95d3-4849-ba4c-290dad1558bb"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["d008354e-3f73-4456-a3d8-4591d924acb2"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"3a752342-0a3b-4511-b284-5003ab1d2615","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T15:34:17Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=oauth-secret-generator-r879t namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/oauth-secret-generator-r879t resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8833995b-9b83-4b26-83a3-da24a59f102c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:34:28Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-xlzgg namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-xlzgg resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=7265d061-3a09-460e-aaeb-e55df61ee871 user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-06-29T15:34:35Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=image-rbac-proxy-6dcfd4d885-sxdcv namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/image-rbac-proxy-6dcfd4d885-sxdcv resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=42302da2-fdc3-49dd-8fbe-730447eb561f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8d595639-8510-4cf4-a720-6d9f1e64ff24"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"0263a760-e641-4477-89e2-9ed4ec753e87","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T15:34:35Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=dex-847db78846-c8h2j namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/dex-847db78846-c8h2j resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b96e6491-71e2-47d7-a397-dc14e93b57d6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8d595639-8510-4cf4-a720-6d9f1e64ff24"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"0263a760-e641-4477-89e2-9ed4ec753e87","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T15:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712455 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712455 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=3dedac7d-c8cd-4bd7-8aa5-028ca23d831c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712455-8zsjj namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712455-8zsjj resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=7180413a-3533-4d40-8653-8fa2d0f1dbc1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:36:32Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 15:36:32 http: TLS handshake error from 10.129.0.2:40344: EOF logger=webhooks/server v=0 2026-06-29T15:36:32Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 15:36:32 http: TLS handshake error from 10.128.0.2:37396: EOF logger=webhooks/server v=0 2026-06-29T15:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712460 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712460 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=3f59dc3f-8444-4cc7-98d1-22ae9be15767 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712460 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712460 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a828d8b9-65c3-4bca-a7d4-0bbdc37e7bd1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:40:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 15:40:00 http: TLS handshake error from 10.129.0.2:54044: EOF logger=webhooks/server v=0 2026-06-29T15:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712460-xsrbr namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712460-xsrbr resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a4245e12-db7c-4e84-aec4-d3fa0bb3a195 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712460-hb28q namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712460-hb28q resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=88ea1c08-6491-432f-acd8-8f98019a1b11 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712465 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712465 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=51262339-6084-4f85-bac0-98dcdea82945 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712465-bx6bp namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712465-bx6bp resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=85d0bf93-bb6e-415f-b9c2-072e389f8504 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712470 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712470 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=565d4ef6-5a7b-4ebd-8b13-ebee3e43f8a9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712470 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712470 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4e2e6f74-5346-42fa-aee1-56f8b014ff85 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:50:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 15:50:00 http: TLS handshake error from 10.130.0.2:50512: EOF logger=webhooks/server v=0 2026-06-29T15:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712470-szszd namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712470-szszd resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=e47174c6-b971-4265-b51c-a79b316dc237 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712470-d2cql namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712470-d2cql resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=fa929bce-3fe9-4c5b-a1e4-8edc2707a2ee user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T15:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712475 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712475 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=dc6fcaad-ac18-483d-838d-6567d9e116db user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T15:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712475-pq9gl namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712475-pq9gl resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1e9bd27f-c174-4085-a63e-d1fbed0f5afb user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=dfcbdeee-3118-4fe7-b2a6-1788bdb6182f"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T16:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=namespace-claim-cleaner-29712480 namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Job/namespace-claim-cleaner-29712480 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=79420cd2-419b-4a19-ac68-d3c034a15371 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T16:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=create-dependencyupdatecheck-29712480 namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Job/create-dependencyupdatecheck-29712480 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8a7b4fec-e404-41b0-b760-0c288519a762 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T16:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 16:00:00 http: TLS handshake error from 10.130.0.2:58268: EOF logger=webhooks/server v=0 2026-06-29T16:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712480 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712480 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=17804af9-f962-4109-b325-83291f6f48cc user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T16:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712480 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712480 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b3f896c5-b57d-4900-aa4d-e1d80c678fe0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=f99702ed-0323-41b8-96ec-7c39d79f0ad3"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T16:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=namespace-claim-cleaner-29712480-z4xc4 namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Pod/namespace-claim-cleaner-29712480-z4xc4 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8a64a08b-5eff-4c13-9023-d5ad0702e3c3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48c38bcf-1343-4d5e-a74c-3861d84be010"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T16:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712480-hmf96 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712480-hmf96 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=63d4bc91-c0d2-49ee-994e-70c351bb56b9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48c38bcf-1343-4d5e-a74c-3861d84be010"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T16:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=create-dependencyupdatecheck-29712480-f6hsq namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Pod/create-dependencyupdatecheck-29712480-f6hsq resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=69b50ad8-0961-420f-bce2-e33f7bf5576e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48c38bcf-1343-4d5e-a74c-3861d84be010"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T16:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712480-xp25w namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712480-xp25w resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=55354182-5bdc-4ea2-b62b-933079013db7 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48c38bcf-1343-4d5e-a74c-3861d84be010"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T16:00:20Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=renovate-06291600-30829921-build-pod namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Pod/renovate-06291600-30829921-build-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5eca5fee-d3ec-4ade-9b0c-934628d90563 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=b20c19e7-0cb5-4eba-9890-f2cf5a65c708"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T16:00:21Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=renovate-06291600-26e86396-build-pod namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Pod/renovate-06291600-26e86396-build-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=78eb0d3d-1fd1-4a60-81e5-c2c78bed5f24 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=b20c19e7-0cb5-4eba-9890-f2cf5a65c708"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["20a0dc94-16dc-4d6e-b1e5-15c7ef92e9c6"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"bed4901c-17f1-4cb7-8cfc-66d31f5bdff0","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T16:04:29Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-2gxkp namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-2gxkp resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=aace8ae7-6ede-4e24-a9aa-eaf226e0c144 user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-06-29T16:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712485 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712485 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=cc99d4e3-5d03-4066-a4d7-c70ef68a05d7 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2b1b1dfa-5337-4908-9166-35ed1835f05e"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T16:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712485-srhq8 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712485-srhq8 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d8d9b6e0-e9e3-4955-af0f-5aa52cc1c9b8 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48c38bcf-1343-4d5e-a74c-3861d84be010"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T16:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712490 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712490 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f82f6d9f-da27-4a4c-8439-0da2c79f23fc user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2b1b1dfa-5337-4908-9166-35ed1835f05e"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T16:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712490 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712490 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c7a42633-8fe2-406c-b1e3-dbf2f605c715 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2b1b1dfa-5337-4908-9166-35ed1835f05e"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T16:10:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 16:10:00 http: TLS handshake error from 10.128.0.2:60986: EOF logger=webhooks/server v=0 2026-06-29T16:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712490-w9m9x namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712490-w9m9x resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4ab7fefc-8b11-43ab-9be2-e16275c6c7ab user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48c38bcf-1343-4d5e-a74c-3861d84be010"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T16:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712490-8zzdz namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712490-8zzdz resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=09873834-34d0-4fbb-a097-dd4284072ac5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48c38bcf-1343-4d5e-a74c-3861d84be010"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T16:10:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 16:10:00 http: TLS handshake error from 10.129.0.2:45798: EOF logger=webhooks/server v=0 2026-06-29T16:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712495 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712495 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a371f5ac-fa63-4f3e-a406-2b537f02a24f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2b1b1dfa-5337-4908-9166-35ed1835f05e"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c6d89f29-0e26-4043-809d-14f0e116d3b6","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T16:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712495-qs77t namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712495-qs77t resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0a59ff7e-d356-4acd-a794-23a5ede4428f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=48c38bcf-1343-4d5e-a74c-3861d84be010"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"545a2870-9313-4bf8-afbe-05ee56f36c82","username":"system:serviceaccount:kube-system:job-controller"} v=2