2026-06-29T11:30:53Z TRC kyverno/pkg/version/version.go:49 > version hash=--- logger=setup/version v=2 version=1.25.8 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > add_dir_header=false logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > admissionReports=false logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > allowInsecureRegistry=false logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > alsologtostderr=false logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > autoDeleteWebhooks=false logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > autoUpdateWebhooks=true logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > backgroundServiceAccountName=system:serviceaccount:konflux-kyverno:kyverno-background-controller logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > caSecretName=konflux-kyverno-svc.konflux-kyverno.svc.kyverno-tls-ca logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > cleanupServerPort=9443 logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > clientRateLimitBurst=200 logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > clientRateLimitQPS=100 logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > controllerRuntimeMetricsAddress=:8080 logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > crdWatcher=false logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > disableLogColor=false logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > disableMetrics=false logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > dumpPatches= logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > dumpPayload=false logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > enableConfigMapCaching=true logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > enableDeferredLoading= logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > enablePolicyException=false logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > enableReporting= logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > enableTracing=false logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > enableTuf=false logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > eventsRateLimitBurst=2000 logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > eventsRateLimitQPS=1000 logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > exceptionNamespace= logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > forceFailurePolicyIgnore= logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > generateMutatingAdmissionPolicy= logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > generateValidatingAdmissionPolicy= logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > imagePullSecrets= logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheEnabled=true logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheMaxSize=1000 logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > imageVerifyCacheTTLDuration=1h0m0s logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > kubeconfig= logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > leaderElectionRetryPeriod=26s logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > log_backtrace_at=:0 logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > log_dir= logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > log_file= logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > log_file_max_size=1800 logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag loggingFormat=text v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag loggingtsFormat=default v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag logtostderr=true v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAPICallResponseLength=2000000 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAdmissionReports=1000 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAuditCapacity=1000 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxAuditWorkers=8 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag maxQueuedEvents=1000 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag metricsPort=8000 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag omitEvents=PolicyApplied,PolicySkipped v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag one_output=false v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag otelCollector=opentelemetrycollector.kyverno.svc.cluster.local v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag otelConfig=prometheus v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profile=false v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profileAddress= v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag profilePort=6060 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag protectManagedResources= v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag registryCredentialHelpers=default,google,amazon,azure,github v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag renewBefore=360h0m0s v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag reportsServiceAccountName= v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag resyncPeriod=15m0s v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag serverIP= v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag servicePort=443 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag skip_headers=false v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag skip_log_headers=false v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag stderrthreshold=2 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tlsSecretName=konflux-kyverno-svc.konflux-kyverno.svc.kyverno-tls-pair v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingAddress= v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingCreds= v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tracingPort=4317 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag transportCreds= v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufMirror=https://tuf-repo-cdn.sigstore.dev v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufRoot= v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag tufRootRaw= v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 vmodule= 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookRegistrationTimeout=2m0s 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookServerPort=9443 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/flag.go:301 > logger=setup/flag v=2 webhookTimeout=10 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/maxprocs.go:12 > setup maxprocs... logger=setup/maxprocs v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/signal.go:16 > setup signals... logger=setup/signals v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/kube-client qps=100 v=2 2026-06-29T11:30:53Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=true feature=InOrderInformers logger=klog v=1 2026-06-29T11:30:53Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=WatchListClient logger=klog v=1 2026-06-29T11:30:53Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=ClientsAllowCBOR logger=klog v=1 2026-06-29T11:30:53Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=ClientsPreferCBOR logger=klog v=1 2026-06-29T11:30:53Z DBG cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/features/envvar.go:172 > Feature gate default state enabled=false feature=InformerResourceVersion logger=klog v=1 2026-06-29T11:30:53Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/metrics.go:18 > setup metrics... collector=opentelemetrycollector.kyverno.svc.cluster.local creds= logger=setup/metrics otel=prometheus port=8000 v=2 2026-06-29T11:30:53Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:417 > defaultRegistry configured defaultRegistry=docker.io logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:433 > enableDefaultRegistryMutation configured enableDefaultRegistryMutation=true logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:442 > excludedGroups configured excludeGroups=["system:nodes"] includeGroups=[] logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:447 > excludeUsernames not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:455 > excludeRoles not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:463 > excludeClusterRoles not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:479 > generateSuccessEvents configured generateSuccessEvents=false logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:493 > webhooks configured logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 webhooks="{\"namespaceSelector\":{\"matchExpressions\":[{\"key\":\"kubernetes.io/metadata.name\",\"operator\":\"NotIn\",\"values\":[\"kube-system\"]},{\"key\":\"kubernetes.io/metadata.name\",\"operator\":\"NotIn\",\"values\":[\"konflux-kyverno\"]}],\"matchLabels\":null}}" 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:507 > webhookAnnotations configured logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 webhookAnnotations="{\"admissions.enforcer/disabled\":\"true\"}" 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:513 > webhookLabels not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:527 > matchConditions not set logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:548 > enableDefaultRegistryMutation configured enableDefaultRegistryMutation=true logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T11:30:53Z TRC kyverno/pkg/config/config.go:563 > maxContextSize not set, using default default=2097152 logger=config name=konflux-kyverno namespace=konflux-kyverno v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/registry.go:18 > setup registry client... insecure=false logger=setup/registry-client secrets= v=2 2026-06-29T11:30:53Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/imageverifycache.go:10 > setup image verify cache... enabled=true logger=setup/image-verify-cache maxsize=1000 ttl=1h0m0s v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/kube-client qps=100 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/client.go:60 > create kyverno client... burst=200 kubeconfig= logger=setup/kyverno-client qps=100 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/client.go:68 > create dynamic client... burst=200 kubeconfig= logger=setup/dynamic-client qps=100 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/client.go:84 > create apiserver client... burst=200 kubeconfig= logger=setup/apiserver-client qps=100 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/client.go:76 > create metadata client... burst=200 kubeconfig= logger=setup/metadata-client qps=100 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/client.go:92 > create the kyverno dynamic client... burst=200 kubeconfig= logger=setup/d-client qps=100 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/client.go:100 > create the events client... burst=200 kubeconfig= logger=setup/events-client qps=100 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/client.go:44 > create kube client... burst=200 kubeconfig= logger=setup/events-client/kube-client qps=100 v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/reporting.go:13 > setting up reporting... enableReporting= generate=false imageVerify=false logger=setup/setup-reporting mutate=false mutateExisiting=false v=2 validate=false 2026-06-29T11:30:53Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-06-29T11:30:53Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Secret v=2 2026-06-29T11:30:53Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Deployment v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/engine.go:65 > setup exception selector... enablePolicyException=false exceptionNamespace= logger=setup/exception-selector v=2 2026-06-29T11:30:53Z TRC kyverno/cmd/internal/engine.go:94 > setup config map resolver... enableConfigMapCaching=true logger=setup/configmap-resolver v=2 2026-06-29T11:30:53Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ConfigMap v=2 2026-06-29T11:30:54Z TRC kyverno/cmd/internal/engine.go:46 > setup engine... logger=setup/engine v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Deployment v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2alpha1.GlobalContextEntry v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Policy v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterPolicy v=2 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/metrics/server/server.go:208 > Starting metrics server logger=controller-runtime/metrics v=0 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/metrics/server/server.go:247 > Serving metrics server bindAddress=:8080 logger=controller-runtime/metrics secure=false v=0 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy source="kind source: *v1alpha1.ValidatingPolicy" v=0 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy source="kind source: *v1alpha1.ImageValidatingPolicy" v=0 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:246 > Starting EventSource controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy source="kind source: *v1alpha1.MutatingPolicy" v=0 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.PolicyException v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterRoleBinding v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Namespace v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.RoleBinding v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2.UpdateRequest v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.GeneratingPolicy v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ValidatingPolicy v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ImageValidatingPolicy v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=controller-runtime/cache reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.MutatingPolicy v=2 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy v=0 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=imagevalidatingpolicy controllerGroup=policies.kyverno.io controllerKind=ImageValidatingPolicy v=0 worker count=1 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy v=0 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=mutatingpolicy controllerGroup=policies.kyverno.io controllerKind=MutatingPolicy v=0 worker count=1 2026-06-29T11:30:54Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup name=kyverno-events v=2 workers=3 2026-06-29T11:30:54Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup name=global-context v=2 workers=1 2026-06-29T11:30:54Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/controllers name=policycache-controller v=2 workers=3 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/leaderelection/leaderelection.go:257 > attempting to acquire leader lease konflux-kyverno/kyverno... logger=klog v=0 2026-06-29T11:30:54Z TRC kyverno/pkg/event/controller.go:106 > start logger=EventGenerator v=2 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/leaderelection/leaderelection.go:271 > successfully acquired lease konflux-kyverno/kyverno logger=klog v=0 2026-06-29T11:30:54Z TRC kyverno/pkg/leaderelection/leaderelection.go:83 > started leading id=kyverno-admission-controller-5cbb799dc8-lrvjz logger=setup/leader-election v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.GeneratingPolicy v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterPolicy v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ValidatingPolicy v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.PolicyException v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Policy v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.Lease v=2 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:186 > Starting Controller controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy v=0 2026-06-29T11:30:54Z INF cachi2/output/deps/gomod/pkg/mod/sigs.k8s.io/controller-runtime@v0.21.0/pkg/internal/controller/controller.go:195 > Starting workers controller=validatingpolicy controllerGroup=policies.kyverno.io controllerKind=ValidatingPolicy v=0 worker count=1 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.MutatingPolicy v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingAdmissionPolicy v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1alpha1.ImageValidatingPolicy v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingAdmissionPolicyBinding v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.MutatingWebhookConfiguration v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ValidatingWebhookConfiguration v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v1.ClusterRole v=2 2026-06-29T11:30:54Z TRC cachi2/output/deps/gomod/pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:430 > Caches populated logger=klog reflector=pkg/mod/k8s.io/client-go@v0.33.3/tools/cache/reflector.go:285 type=*v2.PolicyException v=2 2026-06-29T11:30:54Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=certmanager-controller v=2 workers=1 2026-06-29T11:30:54Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=global-context-webhook-controller v=2 workers=1 2026-06-29T11:30:54Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=status-controller v=2 workers=3 2026-06-29T11:30:54Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=admissionpolicy-generator v=2 workers=2 2026-06-29T11:30:54Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=celexception-webhook-controller v=2 workers=1 2026-06-29T11:30:54Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=exception-webhook-controller v=2 workers=1 2026-06-29T11:30:54Z TRC kyverno/pkg/utils/controller/run.go:58 > starting ... logger=admissionpolicy-generator v=2 2026-06-29T11:30:54Z TRC kyverno/cmd/internal/controller.go:32 > starting controller logger=setup/leader/controllers name=webhook-controller v=2 workers=2 2026-06-29T11:34:26Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:34:26 http: TLS handshake error from 10.129.0.2:35882: EOF logger=webhooks/server v=0 2026-06-29T11:34:26Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:34:26 http: TLS handshake error from 10.130.0.2:57840: EOF logger=webhooks/server v=0 2026-06-29T11:34:26Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:34:26 http: TLS handshake error from 10.128.0.2:45118: EOF logger=webhooks/server v=0 2026-06-29T11:34:26Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:34:26 http: TLS handshake error from 10.129.0.2:35898: EOF logger=webhooks/server v=0 2026-06-29T11:34:26Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:34:26 http: TLS handshake error from 10.130.0.2:57872: EOF logger=webhooks/server v=0 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=init-ns-kubearchiveconfig uid=368e21b7-286a-4f8d-a8cb-ad9fff3a78d2 v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=init-ns-kubearchiveconfig type=ClusterPolicy v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpingress uid=81abe464-623c-45c9-933f-6a395a963ade v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpingress type=ClusterPolicy v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpconsole type=ClusterPolicy v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpconsole uid=a34b3271-e411-4e40-ae96-5e624d2fc62b v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-olm uid=4107141d-6e6a-481c-89a4-755d7febc5a3 v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-olm type=ClusterPolicy v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-ocpmonitoring type=ClusterPolicy v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-ocpmonitoring uid=abf4733f-8d02-4615-828f-725aebe74474 v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-np-samenamespace uid=f9f69319-0322-4442-81e0-1ea73b20f6fd v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-bootstrap-tenant-namespace-rbcm uid=0e29e7e6-0b07-4678-8d10-d63ffbe19308 v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-np-samenamespace type=ClusterPolicy v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-bootstrap-tenant-namespace-rbcm type=ClusterPolicy v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=integration-init-ns-integration uid=454010e9-9852-4407-9b90-5d4af06c77ba v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=integration-init-ns-integration type=ClusterPolicy v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-generate-konflux-viewer-access uid=6d7c804f-cbc4-484a-9bdf-cf1443b61cb4 v=2 2026-06-29T11:34:26Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-generate-konflux-viewer-access type=ClusterPolicy v=2 2026-06-29T11:34:27Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-validate-restrict-binding-sysauth-releng uid=33fdf814-f4cd-49e3-b2fb-16607f132583 v=2 2026-06-29T11:34:27Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-validate-restrict-binding-sysauth-releng type=ClusterPolicy v=2 2026-06-29T11:34:27Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=konflux-rbac-validate-restrict-binding-system-authenticated uid=840ec1ff-0983-4102-b23c-f3560564f503 v=2 2026-06-29T11:34:27Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=konflux-rbac-validate-restrict-binding-system-authenticated type=ClusterPolicy v=2 2026-06-29T11:34:27Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"konflux-rbac-validate-restrict-binding-sysauth-releng\": the object has been modified; please apply your changes to the latest version and try again" konflux-rbac-validate-restrict-binding-sysauth-releng=status 2026-06-29T11:34:27Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"konflux-rbac-validate-restrict-binding-system-authenticated\": the object has been modified; please apply your changes to the latest version and try again" konflux-rbac-validate-restrict-binding-system-authenticated=status 2026-06-29T11:34:27Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=restrict-binding-system-groups type=ClusterPolicy v=2 2026-06-29T11:34:27Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=restrict-binding-system-groups uid=216171f4-eb92-4c21-9388-69d3eb72ce68 v=2 2026-06-29T11:34:27Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"restrict-binding-system-groups\": the object has been modified; please apply your changes to the latest version and try again" restrict-binding-system-groups=status 2026-06-29T11:34:27Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=restrict-docker-io-images uid=deec06b4-7205-4f25-a70d-d06b4bed0ec1 v=2 2026-06-29T11:34:27Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=tekton-taskrun-resource-policy uid=dfb2338f-d49f-45f2-bb81-7a18d19c4ad7 v=2 2026-06-29T11:34:27Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=restrict-docker-io-images type=ClusterPolicy v=2 2026-06-29T11:34:27Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=tekton-taskrun-resource-policy type=ClusterPolicy v=2 2026-06-29T11:34:27Z ERR kyverno/pkg/controllers/admissionpolicygenerator/controller.go:242 > failed to update cluster policy status error="Operation cannot be fulfilled on clusterpolicies.kyverno.io \"restrict-docker-io-images\": the object has been modified; please apply your changes to the latest version and try again" restrict-docker-io-images=status 2026-06-29T11:34:33Z TRC kyverno/pkg/controllers/generic/logging/controller.go:45 > resource added logger=setup/cluster-policy name=bootstrap-tenant-namespace-queue type=ClusterPolicy v=2 2026-06-29T11:34:33Z TRC kyverno/pkg/controllers/admissionpolicygenerator/cpol.go:12 > policy created kind=ClusterPolicy logger=admissionpolicy-generator name=bootstrap-tenant-namespace-queue uid=a4dabca9-775c-4cbc-a8f8-8b6ff268aff8 v=2 2026-06-29T11:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712215 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712215 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c64aa4ee-78f5-48e4-9e5f-915af3c2f7fb user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5db93922-f31a-4ff0-bc52-273c3c4aa10d"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T11:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712215-pvgxc namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712215-pvgxc resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a6ea177e-0e9b-487a-9460-b65bd34c80f8 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T11:37:32Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=tekton-chains-signing-secret namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Job/tekton-chains-signing-secret resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=d613d882-1409-47f0-aefc-6097deacedf1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2587d9d5-0e75-43d5-94ca-b924d2020662"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["10a82451-f565-43e0-8576-32a05e3a7a2e"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"1f4f1f33-3745-42c8-996b-876954ee699b","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T11:37:32Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-chains-signing-secret-nk6qr namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-chains-signing-secret-nk6qr resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9fd0a877-0533-47c4-83a8-056ad6cf6503 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T11:38:45Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:38:45 http: TLS handshake error from 10.130.0.2:42612: EOF logger=webhooks/server v=0 2026-06-29T11:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712220 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712220 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=221a5824-9168-47e8-9011-3dcaae98693f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5db93922-f31a-4ff0-bc52-273c3c4aa10d"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T11:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712220 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712220 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=38604366-177b-4298-af25-ba934a42801d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5db93922-f31a-4ff0-bc52-273c3c4aa10d"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T11:40:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:40:00 http: TLS handshake error from 10.129.0.2:60184: EOF logger=webhooks/server v=0 2026-06-29T11:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712220-hfcxm namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712220-hfcxm resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ce64fe55-94a0-46e3-96d2-3a77eb5a5e3b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T11:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712220-7cgsk namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712220-7cgsk resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ba774495-4be2-4565-a9ab-299f3f0c7d12 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T11:40:13Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="apps/v1, Kind=Deployment" gvr="apps/v1, Resource=deployments" kind=Deployment logger=webhooks/resource/validate name=tekton-results-watcher namespace=tekton-results operation=CREATE policy=restrict-docker-io-images resource=tekton-results/Deployment/tekton-results-watcher resource.gvk="apps/v1, Kind=Deployment" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=01480edb-dd0b-4859-8ec1-0eb7afb0199a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=2587d9d5-0e75-43d5-94ca-b924d2020662"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["10a82451-f565-43e0-8576-32a05e3a7a2e"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"1f4f1f33-3745-42c8-996b-876954ee699b","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T11:40:13Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-results-watcher-55667bb668-fmcf2 namespace=tekton-results operation=CREATE policy=restrict-docker-io-images resource=tekton-results/Pod/tekton-results-watcher-55667bb668-fmcf2 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b6b741bf-82ba-4cfc-b207-af41dea65cad user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=47c2fc06-41da-48be-a3b8-ee27031bbec4"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"7ea15f83-aeeb-4c01-8952-68270127df79","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T11:40:29Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:40:29 http: TLS handshake error from 10.129.0.2:36060: EOF logger=webhooks/server v=0 2026-06-29T11:40:29Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:40:29 http: TLS handshake error from 10.129.0.2:36046: EOF logger=webhooks/server v=0 2026-06-29T11:40:29Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:40:29 http: TLS handshake error from 10.129.0.2:36068: EOF logger=webhooks/server v=0 2026-06-29T11:40:29Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:40:29 http: TLS handshake error from 10.130.0.2:54164: EOF logger=webhooks/server v=0 2026-06-29T11:40:30Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:40:30 http: TLS handshake error from 10.128.0.2:55458: EOF logger=webhooks/server v=0 2026-06-29T11:41:27Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:41:27 http: TLS handshake error from 10.129.0.2:58428: EOF logger=webhooks/server v=0 2026-06-29T11:41:27Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:41:27 http: TLS handshake error from 10.128.0.2:49270: EOF logger=webhooks/server v=0 2026-06-29T11:41:27Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:41:27 http: TLS handshake error from 10.130.0.2:35352: EOF logger=webhooks/server v=0 2026-06-29T11:41:27Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:41:27 http: TLS handshake error from 10.130.0.2:35362: EOF logger=webhooks/server v=0 2026-06-29T11:41:27Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:41:27 http: TLS handshake error from 10.130.0.2:35378: EOF logger=webhooks/server v=0 2026-06-29T11:41:27Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:41:27 http: TLS handshake error from 10.128.0.2:49282: EOF logger=webhooks/server v=0 2026-06-29T11:41:37Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="apps/v1, Kind=StatefulSet" gvr="apps/v1, Resource=statefulsets" kind=StatefulSet logger=webhooks/resource/validate name=affinity-assistant-0ab4a7c45b namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/StatefulSet/affinity-assistant-0ab4a7c45b resource.gvk="apps/v1, Kind=StatefulSet" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=cb114fb9-3582-4874-895e-2a24c2b15a6d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:41:37Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:statefulset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=affinity-assistant-0ab4a7c45b-0 namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/affinity-assistant-0ab4a7c45b-0 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c0eb2d7c-6393-4deb-afcf-2bd388164439 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=24e0ebba-5653-4be0-8d64-3bfdd541d2f1"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"c40c0de1-1fd8-4007-9cbe-4cd31f6adbe6","username":"system:serviceaccount:kube-system:statefulset-controller"} v=2 2026-06-29T11:41:37Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-xvsujenlfw-init-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/buildah-demo-xvsujenlfw-init-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=beac667f-4947-4565-a836-a2a96373c487 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:41:53Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-xvsujenlfw-clone-repository-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/buildah-demo-xvsujenlfw-clone-repository-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=951fd0bf-b39e-4db5-abef-aed68e3ee9e3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:41:54Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-4xz7h namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-4xz7h resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0f309a2b-4b70-4953-aff9-e4f88ef298a3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=47c2fc06-41da-48be-a3b8-ee27031bbec4"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"7ea15f83-aeeb-4c01-8952-68270127df79","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T11:42:17Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=buildah-demo-xvsujenlfw-prefetch-dependencies-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=1de3f022-25d1-429e-b365-9f4ed1089276 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:42:17Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=buildah-demo-xvsujenlfw-prefetch-dependencies-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=39510067-3f9b-482a-bb53-c0dc89cb1417 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:42:17Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-xvsujenlfw-prefetch-dependencies-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/buildah-demo-xvsujenlfw-prefetch-dependencies-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a7bb9e1b-e346-4563-853c-7051872607d8 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:42:24Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-kcvbd namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-kcvbd resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f6505a15-aab7-4fac-a9c3-8add9473da3c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=47c2fc06-41da-48be-a3b8-ee27031bbec4"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"7ea15f83-aeeb-4c01-8952-68270127df79","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T11:42:35Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-xvsujenlfw-build-container-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/buildah-demo-xvsujenlfw-build-container-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a803748e-e122-4afd-8436-920cee3e8804 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:43:54Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=tekton-pipelines-webhook-5b886bbf8b-mx9hd namespace=openshift-pipelines operation=CREATE policy=restrict-docker-io-images resource=openshift-pipelines/Pod/tekton-pipelines-webhook-5b886bbf8b-mx9hd resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=987ec89d-dbf7-49df-afcf-2c343f6fe734 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=47c2fc06-41da-48be-a3b8-ee27031bbec4"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"7ea15f83-aeeb-4c01-8952-68270127df79","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T11:44:32Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-xvsujenlfw-build-image-index-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/buildah-demo-xvsujenlfw-build-image-index-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2df9ced0-4731-4e64-b4c9-288c942e7d05 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712225 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712225 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=61bf1c6c-a8c0-4169-939a-88ef349151eb user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5db93922-f31a-4ff0-bc52-273c3c4aa10d"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T11:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712225-pfqn6 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712225-pfqn6 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=718b5e05-2b5b-4d9c-9fda-5ad5d7b0b93c user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T11:45:14Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:45:14 http: TLS handshake error from 10.130.0.2:55712: EOF logger=webhooks/server v=0 2026-06-29T11:45:14Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-xvsujenlfw-apply-tags-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/buildah-demo-xvsujenlfw-apply-tags-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=be840eba-f5ee-4346-abfb-ba8511f15197 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:45:14Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:45:14 http: TLS handshake error from 10.129.0.2:40986: EOF logger=webhooks/server v=0 2026-06-29T11:45:14Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=buildah-demo-xvsujenlfw-push-dockerfile-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/buildah-demo-xvsujenlfw-push-dockerfile-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b0d353b7-b7d7-4087-a348-5d7a232c8273 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:45:34Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-f12d89953a4f0713357be7cbfd1bfdbf-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=f178bb09-c08f-499c-925e-f30de4be3b10 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:45:34Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-f12d89953a4f0713357be7cbfd1bfdbf-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=bddedea1-ffcd-448f-a1d1-19285761fb50 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:45:34Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-f12d89953a4f0713357be7cbfd1bfdbf-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/verify-enterprise-contract-f12d89953a4f0713357be7cbfd1bfdbf-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=7c3b71d5-1d84-430b-a2ff-fb3eb3ef3a04 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:45:58Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-53493a7dcec58abe98b1e4e4a04d7835-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=f6651502-8d88-4e1e-8e39-3fbeba6a3142 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:45:58Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-53493a7dcec58abe98b1e4e4a04d7835-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=63ea42bb-e9bc-4d25-acb7-f6ef62c3ec66 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:45:58Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-53493a7dcec58abe98b1e4e4a04d7835-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/verify-enterprise-contract-53493a7dcec58abe98b1e4e4a04d7835-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=47199c46-baf1-4fd0-abbd-171cda229731 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:46:13Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-63973de69fce92ff398e3c969dbcca20-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=e7358cdf-c869-4cdb-b988-a634b06a0cff user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:46:13Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-63973de69fce92ff398e3c969dbcca20-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=a15a3725-3974-45f2-80a1-bac379c29b9e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:46:13Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-63973de69fce92ff398e3c969dbcca20-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/verify-enterprise-contract-63973de69fce92ff398e3c969dbcca20-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0cf8d319-75a4-463e-90ac-8ecec4233567 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:46:29Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-42b67cdf6749231263e44796f32d2d43-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=c0e3773e-8385-4397-8e55-49db67a0e752 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:46:30Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-42b67cdf6749231263e44796f32d2d43-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=3beeaccc-36ae-47b2-b2ef-a03a7e53b851 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:46:30Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-42b67cdf6749231263e44796f32d2d43-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/verify-enterprise-contract-42b67cdf6749231263e44796f32d2d43-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=33ebeea5-98a7-499f-ad66-b4c795f81b01 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:46:42Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-3a5fd7c2273ff6a05c66cdbcd0685a5f-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=f4037a01-7c43-4808-bc39-c591efc7dd79 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:46:42Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-3a5fd7c2273ff6a05c66cdbcd0685a5f-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=049b13fa-3030-452a-aaa8-e22a3a392b0d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:46:42Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-3a5fd7c2273ff6a05c66cdbcd0685a5f-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/verify-enterprise-contract-3a5fd7c2273ff6a05c66cdbcd0685a5f-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4687f214-5c7a-44c0-bebf-ddfaab69bc7a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:46:56Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-4f08be729b76691c2afa56e2b471b61f-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=797b091c-7f53-456b-b24f-7d0e070a1940 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:46:56Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-4f08be729b76691c2afa56e2b471b61f-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=d5a5536e-9564-4602-b665-d21429dbaab6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:46:56Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-4f08be729b76691c2afa56e2b471b61f-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/verify-enterprise-contract-4f08be729b76691c2afa56e2b471b61f-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8998a294-b361-4e35-9967-fd5205c9bc9e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:47:23Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-07c08f6149467711782bfd991e51ccea-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=0b963a48-6663-4a90-86d1-67f65dbccbec user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:47:23Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-07c08f6149467711782bfd991e51ccea-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=12039458-6477-4f48-bea7-5853d50c1e01 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:47:23Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-07c08f6149467711782bfd991e51ccea-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/verify-enterprise-contract-07c08f6149467711782bfd991e51ccea-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=dd8703c6-5478-4626-91eb-41978d8bb14b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:47:59Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-6c36e1a26435fe2c616f70c5cb799a2a-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=1388b9f1-88d0-49fe-95ad-1fa46cf0d615 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:47:59Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-6c36e1a26435fe2c616f70c5cb799a2a-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=0fccbc00-ef58-43cc-9358-22c032ff1004 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:47:59Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-6c36e1a26435fe2c616f70c5cb799a2a-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/verify-enterprise-contract-6c36e1a26435fe2c616f70c5cb799a2a-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ba6951a8-f8e3-4bd0-9246-3158351782af user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:48:15Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-027e6bceeb50916347190ba582b2b5dd-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=506d8c32-9e41-42d9-b826-662407d31211 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:48:15Z TRC kyverno/pkg/webhooks/resource/mutation/mutation.go:134 > mutation rules from policy applied successfully URLParams= clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/mutate name=verify-enterprise-contract-027e6bceeb50916347190ba582b2b5dd-pod namespace=chains-e2e-nsqz operation=CREATE policy=tekton-taskrun-resource-policy resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] rules=["set-task-resources"] uid=adb94f34-2d0d-4fea-83fa-8dba56b174d8 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:48:15Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=verify-enterprise-contract-027e6bceeb50916347190ba582b2b5dd-pod namespace=chains-e2e-nsqz operation=CREATE policy=restrict-docker-io-images resource=chains-e2e-nsqz/Pod/verify-enterprise-contract-027e6bceeb50916347190ba582b2b5dd-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a10b0508-de40-4938-a1f8-3440856dd1f5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T11:48:31Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:31 http: TLS handshake error from 10.129.0.2:42118: EOF logger=webhooks/server v=0 2026-06-29T11:48:31Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:31 http: TLS handshake error from 10.129.0.2:42120: EOF logger=webhooks/server v=0 2026-06-29T11:48:31Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:31 http: TLS handshake error from 10.129.0.2:42124: EOF logger=webhooks/server v=0 2026-06-29T11:48:31Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:31 http: TLS handshake error from 10.128.0.2:59388: EOF logger=webhooks/server v=0 2026-06-29T11:48:32Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:32 http: TLS handshake error from 10.130.0.2:40782: EOF logger=webhooks/server v=0 2026-06-29T11:48:32Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:32 http: TLS handshake error from 10.130.0.2:40790: EOF logger=webhooks/server v=0 2026-06-29T11:48:32Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:32 http: TLS handshake error from 10.129.0.2:42136: EOF logger=webhooks/server v=0 2026-06-29T11:48:32Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:32 http: TLS handshake error from 10.129.0.2:42158: EOF logger=webhooks/server v=0 2026-06-29T11:48:32Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:32 http: TLS handshake error from 10.128.0.2:59404: EOF logger=webhooks/server v=0 2026-06-29T11:48:35Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:35 http: TLS handshake error from 10.128.0.2:60904: EOF logger=webhooks/server v=0 2026-06-29T11:48:35Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:35 http: TLS handshake error from 10.129.0.2:42164: EOF logger=webhooks/server v=0 2026-06-29T11:48:35Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:35 http: TLS handshake error from 10.129.0.2:42172: EOF logger=webhooks/server v=0 2026-06-29T11:48:35Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:35 http: TLS handshake error from 10.130.0.2:40804: EOF logger=webhooks/server v=0 2026-06-29T11:48:35Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:35 http: TLS handshake error from 10.128.0.2:60918: EOF logger=webhooks/server v=0 2026-06-29T11:48:35Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:35 http: TLS handshake error from 10.128.0.2:60922: EOF logger=webhooks/server v=0 2026-06-29T11:48:35Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:35 http: TLS handshake error from 10.128.0.2:60938: EOF logger=webhooks/server v=0 2026-06-29T11:48:37Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:37 http: TLS handshake error from 10.128.0.2:60968: EOF logger=webhooks/server v=0 2026-06-29T11:48:37Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 11:48:37 http: TLS handshake error from 10.128.0.2:60984: EOF logger=webhooks/server v=0 2026-06-29T11:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712230 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712230 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=47d1d993-ceb7-4fdb-9223-506b509036c0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5db93922-f31a-4ff0-bc52-273c3c4aa10d"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T11:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712230 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712230 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=14b15486-8190-4648-a62d-33156dc9f389 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5db93922-f31a-4ff0-bc52-273c3c4aa10d"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T11:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712230-pndqj namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712230-pndqj resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d9c8e246-8f6d-4d88-9415-6914007f02d9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T11:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712230-mrg4j namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712230-mrg4j resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=bfe45f23-0454-4150-bdfa-550404606310 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T11:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712235 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712235 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8b830b00-d084-4da7-a7f5-5de15db85a5d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5db93922-f31a-4ff0-bc52-273c3c4aa10d"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T11:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712235-mrdjd namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712235-mrdjd resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d98f62bf-389d-46f5-afa4-bf079d250d3b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T11:59:13Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-z976s namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-z976s resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=3965bce7-9d59-4d96-af28-ac44a9bce350 user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-06-29T12:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=namespace-claim-cleaner-29712240 namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Job/namespace-claim-cleaner-29712240 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=eedf125b-de3f-4d84-92a8-b91db92390f7 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5db93922-f31a-4ff0-bc52-273c3c4aa10d"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712240 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712240 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=db550035-e547-4d03-8e38-de4e8fe8f763 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5db93922-f31a-4ff0-bc52-273c3c4aa10d"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=integration-service-snapshot-garbage-collector-29712240 namespace=integration-service operation=CREATE policy=restrict-docker-io-images resource=integration-service/Job/integration-service-snapshot-garbage-collector-29712240 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f9cf8baa-9e4b-4e02-92d7-4dbd4fbaf4c9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5db93922-f31a-4ff0-bc52-273c3c4aa10d"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=create-dependencyupdatecheck-29712240 namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Job/create-dependencyupdatecheck-29712240 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f25267de-be9d-409d-b5d9-a9c8655acde0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5db93922-f31a-4ff0-bc52-273c3c4aa10d"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712240 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712240 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4889f86d-8a1b-4f55-940f-58dae61ad587 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=5db93922-f31a-4ff0-bc52-273c3c4aa10d"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 12:00:00 http: TLS handshake error from 10.130.0.2:43360: EOF logger=webhooks/server v=0 2026-06-29T12:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=namespace-claim-cleaner-29712240-nh6hn namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Pod/namespace-claim-cleaner-29712240-nh6hn resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ba4fda45-b5b4-444d-b59a-7ed69a05d7f9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712240-xkl9r namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712240-xkl9r resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=10554911-2e05-46a7-9c8a-28fd7cf550f3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 12:00:00 http: TLS handshake error from 10.130.0.2:43374: EOF logger=webhooks/server v=0 2026-06-29T12:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=integration-service-snapshot-garbage-collector-29712240-4z2dc namespace=integration-service operation=CREATE policy=restrict-docker-io-images resource=integration-service/Pod/integration-service-snapshot-garbage-collector-29712240-4z2dc resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5a0cc2a5-addc-416c-9d43-a7c4a1c77c14 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712240-l5s2t namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712240-l5s2t resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=370e45d8-d38b-42d1-aa17-be7b4e592abc user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=create-dependencyupdatecheck-29712240-fpxql namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Pod/create-dependencyupdatecheck-29712240-fpxql resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c7ac935f-a031-462b-abe9-4cc53fe0b326 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=50fcf936-aaf8-48c9-ac71-30085567ec22"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:00:15Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=renovate-06291200-7df41f78-build-pod namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Pod/renovate-06291200-7df41f78-build-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=823ff643-a38b-4467-87f5-ad934aeadd6f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77039c7b-f55c-4021-b670-e3560e8b95e7"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-0"],"authentication.kubernetes.io/pod-uid":["51790763-73ab-4eb3-837b-cc47ff814243"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T12:00:16Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","pipelines-scc-role","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-pipelines-controller-cluster-access","tekton-pipelines-controller-tenant-access","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=renovate-06291200-bb0062ca-build-pod namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Pod/renovate-06291200-bb0062ca-build-pod resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-controller","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-pipelines-leader-election","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c3a9c84a-91b5-428d-a1bd-bdabe5474d68 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=35459aba-32c3-40c5-8eb1-10bbe148eb18"],"authentication.kubernetes.io/pod-name":["tekton-pipelines-controller-1"],"authentication.kubernetes.io/pod-uid":["a1f642b2-e902-4d5e-bb13-43e8f78cd8ba"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-pipelines","system:authenticated"],"uid":"acada0dc-c8dc-4a21-9dbe-be8332770fdb","username":"system:serviceaccount:openshift-pipelines:tekton-pipelines-controller"} v=2 2026-06-29T12:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712245 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712245 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=83646056-1b68-4105-87ae-19717f4fa9a0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712245-dqmzx namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712245-dqmzx resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=08e3d4fc-fcfa-4b08-a63d-30aa8082eb32 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712250 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712250 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f16a1e7c-f31e-4941-a912-7041b133f461 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712250 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712250 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0c46e170-96e2-482a-81e1-343f8a759f64 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712250-6dvgf namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712250-6dvgf resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=7b045a81-8cbf-4e64-b9b0-bc7b309fc45e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712250-x542p namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712250-x542p resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=c967dc81-0d76-4b5a-8f73-eeab51ee0ddd user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712255 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712255 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=d2d639c3-3d6e-45ba-9c3b-6998b1a983e3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:15:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712255-5t4q2 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712255-5t4q2 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=2ba176bf-b56f-4d05-859f-24baf5c888e5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712260 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712260 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=6c334f8d-4eb6-4bfb-8be0-a9d073287d69 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712260 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712260 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a71c14e0-ecb5-408c-a23b-f1a7bd7a74ae user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:20:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 12:20:00 http: TLS handshake error from 10.129.0.2:44368: EOF logger=webhooks/server v=0 2026-06-29T12:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712260-kdp75 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712260-kdp75 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=cf71a7a1-22c1-422f-80cc-d7e89a59a9a7 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:20:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712260-8wzm4 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712260-8wzm4 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5361ad74-41d7-4379-8201-3975ad7569f8 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712265 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712265 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b281905e-7cd1-42d5-8928-b8706dc3b9b7 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:25:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712265-rcjlp namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712265-rcjlp resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=4b115a3e-215f-4147-a260-38ef71e666bf user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:28:48Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["admin","appstudio-openshift-gitops-argocd-application-controller","basic-user","cluster-status","console-extensions-reader","crd-manager-for-has","crd-manager-for-integration","crd-manager-for-project-controller","crd-manager-for-release","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","openshift-gitops-apply-tekton-config-parameters","openshift-gitops-jobs-admin","openshift-gitops-openshift-gitops-argocd-application-controller","openshift-minio-apply-tenants","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=oauth-secret-generator namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Job/oauth-secret-generator resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","build-templates:openshift-gitops-argocd-application-controller","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-gitops:openshift-gitops-argocd-application-controller","openshift-operators:tekton-operator-info","openshift-pipelines:openshift-gitops-argocd-application-controller","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:openshift-gitops-argocd-application-controller","tekton-results:tekton-results-info"] uid=55002bf9-7fe4-483d-bf30-b56ff42d0173 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=7284190d-9e6c-4907-99b7-0a736aa7604d"],"authentication.kubernetes.io/pod-name":["openshift-gitops-application-controller-0"],"authentication.kubernetes.io/pod-uid":["10a82451-f565-43e0-8576-32a05e3a7a2e"]},"groups":["system:serviceaccounts","system:serviceaccounts:openshift-gitops","system:authenticated"],"uid":"1f4f1f33-3745-42c8-996b-876954ee699b","username":"system:serviceaccount:openshift-gitops:openshift-gitops-argocd-application-controller"} v=2 2026-06-29T12:28:48Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=oauth-secret-generator-xbpt9 namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/oauth-secret-generator-xbpt9 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=cd0e85bc-89ed-4422-aa0a-04c2128aa1a5 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:29:03Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=image-rbac-proxy-8678f4896c-k988q namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/image-rbac-proxy-8678f4896c-k988q resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=94ae7c87-29ae-4f98-ae31-67b0d637fc47 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4aaced7c-7560-405d-bfd7-2e0e13f7bef8"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"7ea15f83-aeeb-4c01-8952-68270127df79","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T12:29:03Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:replicaset-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=dex-68468fc5c6-f248n namespace=image-rbac-proxy operation=CREATE policy=restrict-docker-io-images resource=image-rbac-proxy/Pod/dex-68468fc5c6-f248n resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=91535694-4e20-442f-ad4b-2a17c718c5e9 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=4aaced7c-7560-405d-bfd7-2e0e13f7bef8"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"7ea15f83-aeeb-4c01-8952-68270127df79","username":"system:serviceaccount:kube-system:replicaset-controller"} v=2 2026-06-29T12:29:19Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-fkqbs namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-fkqbs resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=328649ee-94ce-45b0-8dc7-b67f409cac0a user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-06-29T12:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712270 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712270 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=33069b34-3a8e-437a-9770-5f97efd2b882 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712270 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712270 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=99e966ec-e19d-4753-8121-d73c2fe4d3a3 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712270-msdk2 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712270-msdk2 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b1e31281-09af-4495-a5eb-fe854d606c0a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:30:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712270-8x69h namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712270-8x69h resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=b377c7a8-175e-49a4-b02f-021ce9ca6098 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:30:52Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 12:30:52 http: TLS handshake error from 10.128.0.2:58330: EOF logger=webhooks/server v=0 2026-06-29T12:30:53Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 12:30:53 http: TLS handshake error from 10.128.0.2:58338: EOF logger=webhooks/server v=0 2026-06-29T12:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712275 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712275 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8528ce75-c5e1-4e4b-9e54-cb01895dbae4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:35:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712275-wn2mx namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712275-wn2mx resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=f1cb4df4-a693-4dbe-98ac-c273d8837b84 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712280 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712280 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=398282ea-79ee-4a8d-8bc9-eb4f8d955578 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712280 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712280 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=cfe21650-66ca-44aa-a128-ecb765dfc71b user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712280-nj96q namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712280-nj96q resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=579a2849-e5e8-455a-8b70-9442e9536653 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:40:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712280-z26sq namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712280-z26sq resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=5952350c-7121-4d6f-8ce2-864d4051483d user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712285 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712285 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=223fa4a4-6d40-45d0-b5fc-ddc243888abd user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:45:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712285-mgpfq namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712285-mgpfq resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=0e12428b-8070-43ad-9be3-e5b5e5ddccd6 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712290 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712290 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8b40f43e-b9f2-4101-b311-e97ca714f89f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712290 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712290 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=72fa3104-f721-4416-bc2d-842b8ddf538a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=18f820e2-b6a4-4dbb-8b23-110972f16da9"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712290-lf554 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712290-lf554 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ebe283ab-42f4-4cce-9ae2-916cb241a8c1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:50:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712290-sc2kc namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712290-sc2kc resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=ecd875ea-9581-4895-9f56-916061002066 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=8788a25b-0733-4575-8fd2-297c89a4e9c5"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712295 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712295 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1164b3d4-a96b-4e88-bfce-542b0a71c0fb user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=326991cd-3b97-4d2f-8dc0-10c169d46458"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T12:55:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712295-x6p7n namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712295-x6p7n resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8844cfdb-3520-43a2-923f-b22b5c0a9762 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77b89cda-f82e-460a-87a6-6fcf95f92789"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T12:59:19Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-admin","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:discovery","system:master","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=custom-operators-j8cqd namespace=openshift-marketplace operation=CREATE policy=restrict-docker-io-images resource=openshift-marketplace/Pod/custom-operators-j8cqd resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a217b351-8844-45bb-b7a8-816bb052fa38 user={"groups":["system:masters","system:authenticated"],"username":"system:admin"} v=2 2026-06-29T13:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=namespace-claim-cleaner-29712300 namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Job/namespace-claim-cleaner-29712300 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=fd23db1b-8f61-4b84-85cc-8ecbdbf14c44 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=326991cd-3b97-4d2f-8dc0-10c169d46458"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T13:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712300 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712300 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=85d752d4-09b0-45a4-9bb4-90d7778b5d89 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=326991cd-3b97-4d2f-8dc0-10c169d46458"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T13:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712300 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712300 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=fd2c8d25-81dc-4a09-8c50-6a0f67705354 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=326991cd-3b97-4d2f-8dc0-10c169d46458"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T13:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 13:00:00 http: TLS handshake error from 10.130.0.2:33818: EOF logger=webhooks/server v=0 2026-06-29T13:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 13:00:00 http: TLS handshake error from 10.130.0.2:33820: EOF logger=webhooks/server v=0 2026-06-29T13:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=delete-dependencyupdatechecks-29712300 namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Job/delete-dependencyupdatechecks-29712300 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=1c002e18-d57d-40e2-9fcb-0f70f3e2d68f user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=326991cd-3b97-4d2f-8dc0-10c169d46458"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T13:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 13:00:00 http: TLS handshake error from 10.130.0.2:33806: EOF logger=webhooks/server v=0 2026-06-29T13:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=namespace-claim-cleaner-29712300-vbs6k namespace=crossplane-system operation=CREATE policy=restrict-docker-io-images resource=crossplane-system/Pod/namespace-claim-cleaner-29712300-vbs6k resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=13e6faef-4f3a-47fd-a09d-68bbd8c57289 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77b89cda-f82e-460a-87a6-6fcf95f92789"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T13:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712300-gxp8l namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712300-gxp8l resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=42645246-7838-4423-b30d-cbdac4086a14 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77b89cda-f82e-460a-87a6-6fcf95f92789"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T13:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 13:00:00 http: TLS handshake error from 10.128.0.2:57730: EOF logger=webhooks/server v=0 2026-06-29T13:00:00Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 13:00:00 http: TLS handshake error from 10.129.0.2:45050: EOF logger=webhooks/server v=0 2026-06-29T13:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=delete-dependencyupdatechecks-29712300-r7wv5 namespace=mintmaker operation=CREATE policy=restrict-docker-io-images resource=mintmaker/Pod/delete-dependencyupdatechecks-29712300-r7wv5 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=9fed700d-aa2d-45ac-ac29-2192798ca518 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77b89cda-f82e-460a-87a6-6fcf95f92789"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T13:00:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712300-vrk8h namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712300-vrk8h resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=26849abc-0517-4bbb-ad36-719230116e8e user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77b89cda-f82e-460a-87a6-6fcf95f92789"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T13:03:12Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 13:03:12 http: TLS handshake error from 10.130.0.2:41164: EOF logger=webhooks/server v=0 2026-06-29T13:04:05Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 13:04:05 http: TLS handshake error from 10.130.0.2:37394: EOF logger=webhooks/server v=0 2026-06-29T13:04:06Z INF kyverno/pkg/logging/log.go:180 > 2026/06/29 13:04:06 http: TLS handshake error from 10.129.0.2:60942: EOF logger=webhooks/server v=0 2026-06-29T13:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712305 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712305 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=8b49dc8b-28d4-4a57-932c-eca54fd395a1 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=326991cd-3b97-4d2f-8dc0-10c169d46458"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T13:05:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712305-fffdk namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712305-fffdk resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=019ef899-58cd-465a-8ec8-0ba7b4506330 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77b89cda-f82e-460a-87a6-6fcf95f92789"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T13:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712310 namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Job/osd-delete-backplane-serviceaccounts-29712310 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=a20bf96d-58c2-445e-a0b4-e4f9ccfadce0 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=326991cd-3b97-4d2f-8dc0-10c169d46458"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T13:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:cronjob-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="batch/v1, Kind=Job" gvr="batch/v1, Resource=jobs" kind=Job logger=webhooks/resource/validate name=pipelines-vacuum-29712310 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Job/pipelines-vacuum-29712310 resource.gvk="batch/v1, Kind=Job" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=65c63b55-0c29-45a0-827d-71b1530fc57a user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=326991cd-3b97-4d2f-8dc0-10c169d46458"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"9cea224b-45de-4c50-ac6b-0854613c0600","username":"system:serviceaccount:kube-system:cronjob-controller"} v=2 2026-06-29T13:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=osd-delete-backplane-serviceaccounts-29712310-4xxzb namespace=openshift-backplane operation=CREATE policy=restrict-docker-io-images resource=openshift-backplane/Pod/osd-delete-backplane-serviceaccounts-29712310-4xxzb resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=aee88cf6-4880-4eb4-9b9d-27e93a47e4ab user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77b89cda-f82e-460a-87a6-6fcf95f92789"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2 2026-06-29T13:10:00Z TRC kyverno/pkg/webhooks/resource/validation/validation.go:127 > validation passed URLParams= action=validate clusterroles=["basic-user","cluster-status","console-extensions-reader","enterprisecontract-configmap-viewer-role","enterprisecontractpolicy-viewer-role","helm-chartrepos-viewer","konflux-viewer-user-actions","releaseserviceconfig-role","self-access-reviewer","system:basic-user","system:build-strategy-docker","system:build-strategy-jenkinspipeline","system:build-strategy-source","system:controller:job-controller","system:discovery","system:image-puller","system:oauth-token-deleter","system:openshift:discovery","system:openshift:public-info-viewer","system:openshift:scc:restricted-v2","system:public-info-viewer","system:scope-impersonation","system:service-account-issuer-discovery","system:webhook","tekton-chains-public-key-viewer","tekton-clustertasks-view-role","tekton-clustertriggerbindings-view-role","tekton-config-read-role","tekton-default-pipelines-view","tekton-result-read-role"] gvk="/v1, Kind=Pod" gvr="/v1, Resource=pods" kind=Pod logger=webhooks/resource/validate name=pipelines-vacuum-29712310-tvrz7 namespace=product-kubearchive operation=CREATE policy=restrict-docker-io-images resource=product-kubearchive/Pod/pipelines-vacuum-29712310-tvrz7 resource.gvk="/v1, Kind=Pod" roles=["build-service:build-service-build-pipeline-config-read-only","konflux-info:konflux-public-info-view-role","kube-system:extension-apiserver-authentication-reader","openshift-config-managed:console-public","openshift-config-managed:openshift-network-public-role","openshift-config-managed:system:openshift:oauth-servercert-trust","openshift-operators:tekton-operator-info","openshift-pipelines:pipelines-as-code-info","openshift-pipelines:tekton-chains-info","openshift-pipelines:tekton-default-openshift-pipelines-view","openshift-pipelines:tekton-ecosystem-stepaction-list-role","openshift-pipelines:tekton-ecosystem-task-list-role","openshift-pipelines:tekton-pipelines-info","openshift-pipelines:tekton-triggers-info","openshift:copied-csv-viewer","openshift:pipelines-as-code-templates","openshift:shared-resource-viewer","product-kubearchive:kubearchive-api-url-reader","tekton-results:tekton-results-info"] uid=00d62a73-fb25-4bf3-8ae1-9d48e5970bc4 user={"extra":{"authentication.kubernetes.io/credential-id":["JTI=77b89cda-f82e-460a-87a6-6fcf95f92789"]},"groups":["system:serviceaccounts","system:serviceaccounts:kube-system","system:authenticated"],"uid":"eb16e623-78d7-48b2-9be5-4707916007ea","username":"system:serviceaccount:kube-system:job-controller"} v=2