pod: gh-test-custom-branch-otikki-on-pull-request-fp8sk-init-pod | init container: prepare 2026/03/10 19:22:58 Entrypoint initialization pod: gh-test-custom-branch-otikki-on-pull-request-fp8sk-init-pod | container step-init: time="2026-03-10T19:23:00Z" level=info msg="Using in-cluster config" logger=KubeClient time="2026-03-10T19:23:00Z" level=info msg="[param] ENABLE: false" time="2026-03-10T19:23:00Z" level=info msg="[param] DEFAULT HTTP PROXY: squid.caching.svc.cluster.local:3128" time="2026-03-10T19:23:00Z" level=info msg="[param] DEFAULT NO PROXY: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai" time="2026-03-10T19:23:00Z" level=info msg="[param] HTTP PROXY RESULT PATH: /tekton/results/http-proxy" time="2026-03-10T19:23:00Z" level=info msg="[param] NO PROXY RESULT PATH: /tekton/results/no-proxy" time="2026-03-10T19:23:00Z" level=warning msg="Error while reading config data: failed to get configmap konflux-info/cluster-config: configmaps \"cluster-config\" is forbidden: User \"system:serviceaccount:build-e2e-mkep:build-pipeline-gh-test-custom-branch-otikki\" cannot get resource \"configmaps\" in API group \"\" in the namespace \"konflux-info\"" time="2026-03-10T19:23:00Z" level=info msg="Cache proxy is disabled in param or in backend" time="2026-03-10T19:23:00Z" level=info msg="[result] HTTP PROXY: " time="2026-03-10T19:23:00Z" level=info msg="[result] NO PROXY: " pod: gh-test-custom-branch-otikki-on-pull-request-ph57r-init-pod | init container: prepare 2026/03/10 19:37:27 Entrypoint initialization pod: gh-test-custom-branch-otikki-on-pull-request-ph57r-init-pod | container step-init: time="2026-03-10T19:37:29Z" level=info msg="Using in-cluster config" logger=KubeClient time="2026-03-10T19:37:29Z" level=info msg="[param] ENABLE: false" time="2026-03-10T19:37:29Z" level=info msg="[param] DEFAULT HTTP PROXY: squid.caching.svc.cluster.local:3128" time="2026-03-10T19:37:29Z" level=info msg="[param] DEFAULT NO PROXY: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai" time="2026-03-10T19:37:29Z" level=info msg="[param] HTTP PROXY RESULT PATH: /tekton/results/http-proxy" time="2026-03-10T19:37:29Z" level=info msg="[param] NO PROXY RESULT PATH: /tekton/results/no-proxy" time="2026-03-10T19:37:29Z" level=warning msg="Error while reading config data: failed to get configmap konflux-info/cluster-config: configmaps \"cluster-config\" is forbidden: User \"system:serviceaccount:build-e2e-mkep:build-pipeline-gh-test-custom-branch-otikki\" cannot get resource \"configmaps\" in API group \"\" in the namespace \"konflux-info\"" time="2026-03-10T19:37:29Z" level=info msg="Cache proxy is disabled in param or in backend" time="2026-03-10T19:37:29Z" level=info msg="[result] HTTP PROXY: " time="2026-03-10T19:37:29Z" level=info msg="[result] NO PROXY: " pod: gh-test-custom-branch-otikki-on-push-4lbwx-apply-tags-pod | init container: prepare 2026/03/10 19:57:51 Entrypoint initialization pod: gh-test-custom-branch-otikki-on-push-4lbwx-apply-tags-pod | container step-apply-additional-tags: time="2026-03-10T19:57:54Z" level=info msg="[param] Image URL: quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki:e4e564e004482c0d4d791592992936f49b08bd49" time="2026-03-10T19:57:54Z" level=info msg="[param] Image digest: sha256:1029ecbd4edf32cf788fa69530fc9758e1256e3ff245fc3b99db6b0de358b004" time="2026-03-10T19:57:54Z" level=info msg="[param] image label: konflux.additional-tags" time="2026-03-10T19:57:56Z" level=info msg="Additional tags from 'konflux.additional-tags' image label: test-tag1, test-tag2" {"tags":["test-tag1","test-tag2"]} pod: gh-test-custom-branch-otikki-on-push-4lbwx-build-container-pod | init container: prepare 2026/03/10 19:48:31 Entrypoint initialization pod: gh-test-custom-branch-otikki-on-push-4lbwx-build-container-pod | init container: place-scripts 2026/03/10 19:48:32 Decoded script /tekton/scripts/script-0-kmr7p 2026/03/10 19:48:32 Decoded script /tekton/scripts/script-1-vl9gb 2026/03/10 19:48:32 Decoded script /tekton/scripts/script-2-6xhvc 2026/03/10 19:48:32 Decoded script /tekton/scripts/script-3-9pr72 2026/03/10 19:48:32 Decoded script /tekton/scripts/script-4-v2rx6 pod: gh-test-custom-branch-otikki-on-push-4lbwx-build-container-pod | init container: working-dir-initializer pod: gh-test-custom-branch-otikki-on-push-4lbwx-build-container-pod | container step-build: [2026-03-10T19:48:35,136532062+00:00] Validate context path [2026-03-10T19:48:35,141415557+00:00] Update CA trust [2026-03-10T19:48:35,142919731+00:00] Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' [2026-03-10T19:48:38,159045141+00:00] Prepare Dockerfile Checking if /var/workdir/cachi2/output/bom.json exists. Could not find prefetched sbom. No content_sets found for ICM [2026-03-10T19:48:38,173766637+00:00] Prepare system (architecture: x86_64) [2026-03-10T19:48:38,217024666+00:00] Setup prefetched Trying to pull quay.io/jitesoft/nginx:latest... Getting image source signatures Copying blob sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1 Copying blob sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153 Copying blob sha256:3478266b4865f4efc58d163e64670ca678ab1de9918b00b890093f6426681f7b Copying blob sha256:25dedae430683ba72bb966ec6e4628397823e556b414dc851d526f6dc15e329c Copying config sha256:76f22c7e9ca97dad72702ba040aae927f9d94bfb8bc4960d2c5fdacc021d2e30 Writing manifest to image destination [2026-03-10T19:48:40,665184988+00:00] Unsetting proxy { "com.jitesoft.app.alpine.version": "3.23.3", "com.jitesoft.app.nginx.version": "1.29.5", "com.jitesoft.build.arch": "amd64", "com.jitesoft.build.platform": "linux/amd64", "com.jitesoft.project.registry.uri": "registry.gitlab.com/jitesoft/dockerfiles/nginx", "com.jitesoft.project.repo.issues": "https://gitlab.com/jitesoft/dockerfiles/nginx/issues", "com.jitesoft.project.repo.type": "git", "com.jitesoft.project.repo.uri": "https://gitlab.com/jitesoft/dockerfiles/nginx", "io.artifacthub.package.alternative-locations": "oci://index.docker.io/jitesoft/nginx,oci://ghcr.io/jitesoft/nginx,oci://registry.gitlab.com/jitesoft/dockerfiles/nginx", "io.artifacthub.package.logo-url": "https://jitesoft.com/favicon-96x96.png", "io.artifacthub.package.readme-url": "https://gitlab.com/jitesoft/dockerfiles/nginx/-/raw/master/README.md", "maintainer": "Johannes Tegnér ", "maintainer.org": "Jitesoft", "maintainer.org.uri": "https://jitesoft.com", "org.opencontainers.image.created": "2026-03-10T19:48:38Z", "org.opencontainers.image.description": "Nginx on Alpine linux", "org.opencontainers.image.source": "https://github.com/redhat-appstudio-qe/devfile-sample-hello-world-dqphdu", "org.opencontainers.image.vendor": "Jitesoft", "org.opencontainers.image.version": "1.29.5", "architecture": "x86_64", "vcs-type": "git", "vcs-ref": "e4e564e004482c0d4d791592992936f49b08bd49", "org.opencontainers.image.revision": "e4e564e004482c0d4d791592992936f49b08bd49", "build-date": "2026-03-10T19:48:38Z", "io.buildah.version": "1.42.2", "konflux.additional-tags": "test-tag1, test-tag2" } [2026-03-10T19:48:40,720871611+00:00] Register sub-man Adding the entitlement to the build [2026-03-10T19:48:40,725896078+00:00] Add secrets [2026-03-10T19:48:40,744755352+00:00] Run buildah build [2026-03-10T19:48:40,746503478+00:00] buildah build --volume /tmp/entitlement:/etc/pki/entitlement --security-opt=unmask=/proc/interrupts --label architecture=x86_64 --label vcs-type=git --label vcs-ref=e4e564e004482c0d4d791592992936f49b08bd49 --label org.opencontainers.image.revision=e4e564e004482c0d4d791592992936f49b08bd49 --label org.opencontainers.image.source=https://github.com/redhat-appstudio-qe/devfile-sample-hello-world-dqphdu --label build-date=2026-03-10T19:48:38Z --label org.opencontainers.image.created=2026-03-10T19:48:38Z --annotation org.opencontainers.image.revision=e4e564e004482c0d4d791592992936f49b08bd49 --annotation org.opencontainers.image.source=https://github.com/redhat-appstudio-qe/devfile-sample-hello-world-dqphdu --annotation org.opencontainers.image.created=2026-03-10T19:48:38Z --tls-verify=true --no-cache --ulimit nofile=4096:4096 --http-proxy=false -f /tmp/Dockerfile.odpcWX -t quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki:e4e564e004482c0d4d791592992936f49b08bd49 . STEP 1/6: FROM quay.io/jitesoft/nginx:latest STEP 2/6: ENV PORT="8080" STEP 3/6: LABEL konflux.additional-tags="test-tag1, test-tag2" STEP 4/6: COPY labels.json /usr/share/buildinfo/labels.json STEP 5/6: COPY labels.json /root/buildinfo/labels.json STEP 6/6: LABEL "architecture"="x86_64" "vcs-type"="git" "vcs-ref"="e4e564e004482c0d4d791592992936f49b08bd49" "org.opencontainers.image.revision"="e4e564e004482c0d4d791592992936f49b08bd49" "org.opencontainers.image.source"="https://github.com/redhat-appstudio-qe/devfile-sample-hello-world-dqphdu" "build-date"="2026-03-10T19:48:38Z" "org.opencontainers.image.created"="2026-03-10T19:48:38Z" COMMIT quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki:e4e564e004482c0d4d791592992936f49b08bd49 time="2026-03-10T19:48:41Z" level=warning msg="HEALTHCHECK is not supported for OCI image format and will be ignored. Must use `docker` format" --> 956b530ec395 Successfully tagged quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki:e4e564e004482c0d4d791592992936f49b08bd49 956b530ec395786d084a3483566d114f9585f84e5df2abb2c9feca6d71661841 [2026-03-10T19:48:42,120954296+00:00] Unsetting proxy [2026-03-10T19:48:42,122941394+00:00] Add metadata Recording base image digests used quay.io/jitesoft/nginx:latest quay.io/jitesoft/nginx:latest@sha256:034c99124f4056b4a0a52090c8fb65d3f8cc0f05e3a8206e4f6ffda1a413a75e Getting image source signatures Copying blob sha256:c7fc9b3fc5b8afa626ec8f6c1808c18be428623b72ac7bde77a102a835d44366 Copying blob sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e Copying blob sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef Copying blob sha256:b431ed29c213c3983481ebac7a73e46bc4c57aa8a883d602b321fe3da5d3e187 Copying blob sha256:aea8a640c40be1298b8b5f2c2889fde6829d3d5328d9e75e19d3908d1569fa40 Copying config sha256:956b530ec395786d084a3483566d114f9585f84e5df2abb2c9feca6d71661841 Writing manifest to image destination [2026-03-10T19:48:42,627725490+00:00] End build pod: gh-test-custom-branch-otikki-on-push-4lbwx-build-container-pod | container step-push: [2026-03-10T19:48:43,281944295+00:00] Update CA trust INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' [2026-03-10T19:48:46,018059762+00:00] Convert image [2026-03-10T19:48:46,019575686+00:00] Push image with unique tag Pushing to quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki:gh-test-custom-branch-otikki-on-push-4lbwx-build-container [retry] executing: buildah push --format=docker --retry 3 --tls-verify=true quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki:e4e564e004482c0d4d791592992936f49b08bd49 docker://quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki:gh-test-custom-branch-otikki-on-push-4lbwx-build-container Getting image source signatures Copying blob sha256:c7fc9b3fc5b8afa626ec8f6c1808c18be428623b72ac7bde77a102a835d44366 Copying blob sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e Copying blob sha256:aea8a640c40be1298b8b5f2c2889fde6829d3d5328d9e75e19d3908d1569fa40 Copying blob sha256:b431ed29c213c3983481ebac7a73e46bc4c57aa8a883d602b321fe3da5d3e187 Copying blob sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef Copying config sha256:956b530ec395786d084a3483566d114f9585f84e5df2abb2c9feca6d71661841 Writing manifest to image destination [2026-03-10T19:48:51,082028123+00:00] Push image with git revision Pushing to quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki:e4e564e004482c0d4d791592992936f49b08bd49 [retry] executing: buildah push --format=docker --retry 3 --tls-verify=true --digestfile /workspace/source/image-digest quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki:e4e564e004482c0d4d791592992936f49b08bd49 docker://quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki:e4e564e004482c0d4d791592992936f49b08bd49 Getting image source signatures Copying blob sha256:c7fc9b3fc5b8afa626ec8f6c1808c18be428623b72ac7bde77a102a835d44366 Copying blob sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e Copying blob sha256:aea8a640c40be1298b8b5f2c2889fde6829d3d5328d9e75e19d3908d1569fa40 Copying blob sha256:b431ed29c213c3983481ebac7a73e46bc4c57aa8a883d602b321fe3da5d3e187 Copying blob sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef Copying config sha256:956b530ec395786d084a3483566d114f9585f84e5df2abb2c9feca6d71661841 Writing manifest to image destination sha256:1029ecbd4edf32cf788fa69530fc9758e1256e3ff245fc3b99db6b0de358b004quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki:e4e564e004482c0d4d791592992936f49b08bd49 [retry] executing: kubectl get configmap cluster-config -n konflux-info -o json Error from server (Forbidden): configmaps "cluster-config" is forbidden: User "system:serviceaccount:build-e2e-mkep:build-pipeline-gh-test-custom-branch-otikki" cannot get resource "configmaps" in API group "" in the namespace "konflux-info" [retry] waiting for 1 seconds before attempt 2... [retry] executing: kubectl get configmap cluster-config -n konflux-info -o json Error from server (Forbidden): configmaps "cluster-config" is forbidden: User "system:serviceaccount:build-e2e-mkep:build-pipeline-gh-test-custom-branch-otikki" cannot get resource "configmaps" in API group "" in the namespace "konflux-info" [retry] waiting for 2 seconds before attempt 3... [retry] executing: kubectl get configmap cluster-config -n konflux-info -o json Error from server (Forbidden): configmaps "cluster-config" is forbidden: User "system:serviceaccount:build-e2e-mkep:build-pipeline-gh-test-custom-branch-otikki" cannot get resource "configmaps" in API group "" in the namespace "konflux-info" [retry] waiting for 4 seconds before attempt 4... [retry] executing: kubectl get configmap cluster-config -n konflux-info -o json Error from server (Forbidden): configmaps "cluster-config" is forbidden: User "system:serviceaccount:build-e2e-mkep:build-pipeline-gh-test-custom-branch-otikki" cannot get resource "configmaps" in API group "" in the namespace "konflux-info" [retry] waiting for 8 seconds before attempt 5... [retry] executing: kubectl get configmap cluster-config -n konflux-info -o json Error from server (Forbidden): configmaps "cluster-config" is forbidden: User "system:serviceaccount:build-e2e-mkep:build-pipeline-gh-test-custom-branch-otikki" cannot get resource "configmaps" in API group "" in the namespace "konflux-info" [retry] waiting for 16 seconds before attempt 6... [retry] executing: kubectl get configmap cluster-config -n konflux-info -o json Error from server (Forbidden): configmaps "cluster-config" is forbidden: User "system:serviceaccount:build-e2e-mkep:build-pipeline-gh-test-custom-branch-otikki" cannot get resource "configmaps" in API group "" in the namespace "konflux-info" [retry] waiting for 32 seconds before attempt 7... [retry] executing: kubectl get configmap cluster-config -n konflux-info -o json Error from server (Forbidden): configmaps "cluster-config" is forbidden: User "system:serviceaccount:build-e2e-mkep:build-pipeline-gh-test-custom-branch-otikki" cannot get resource "configmaps" in API group "" in the namespace "konflux-info" [retry] waiting for 64 seconds before attempt 8... [retry] executing: kubectl get configmap cluster-config -n konflux-info -o json Error from server (Forbidden): configmaps "cluster-config" is forbidden: User "system:serviceaccount:build-e2e-mkep:build-pipeline-gh-test-custom-branch-otikki" cannot get resource "configmaps" in API group "" in the namespace "konflux-info" [retry] waiting for 128 seconds before attempt 9... [retry] executing: kubectl get configmap cluster-config -n konflux-info -o json Error from server (Forbidden): configmaps "cluster-config" is forbidden: User "system:serviceaccount:build-e2e-mkep:build-pipeline-gh-test-custom-branch-otikki" cannot get resource "configmaps" in API group "" in the namespace "konflux-info" [retry] waiting for 256 seconds before attempt 10... [retry] executing: kubectl get configmap cluster-config -n konflux-info -o json Error from server (Forbidden): configmaps "cluster-config" is forbidden: User "system:serviceaccount:build-e2e-mkep:build-pipeline-gh-test-custom-branch-otikki" cannot get resource "configmaps" in API group "" in the namespace "konflux-info" [retry] giving up after 10 attempts: max attempts reached Failed to fetch konflux cluster-config, default values will be used Keyless signing is disabled (none of rekorInternalUrl, fulcioInternalUrl, defaultOIDCIssuer, tufInternalUrl are configured in the konflux-info/cluster-config configmap) [2026-03-10T19:57:24,175723296+00:00] End push pod: gh-test-custom-branch-otikki-on-push-4lbwx-build-container-pod | container step-sbom-syft-generate: [2026-03-10T19:57:24,645888012+00:00] Generate SBOM Running syft on the image Running syft on the source code [0000] WARN no explicit name and version provided for directory source, deriving artifact ID from the given path (which is not ideal) [2026-03-10T19:57:27,563415602+00:00] End sbom-syft-generate pod: gh-test-custom-branch-otikki-on-push-4lbwx-build-container-pod | container step-prepare-sboms: [2026-03-10T19:57:27,834456593+00:00] Prepare SBOM [2026-03-10T19:57:27,840161824+00:00] Generate SBOM with mobster Skipping SBOM validation 2026-03-10 19:57:29,456 [INFO] mobster.log: Logging level set to 20 2026-03-10 19:57:29,495 [INFO] mobster.oci: Fetching manifest for quay.io/jitesoft/nginx@sha256:034c99124f4056b4a0a52090c8fb65d3f8cc0f05e3a8206e4f6ffda1a413a75e 2026-03-10 19:57:32,602 [INFO] mobster.cmd.generate.oci_image.contextual_sbom.contextualize: Contextual mechanism won't be used, there is no parent image SBOM. 2026-03-10 19:57:32,602 [INFO] mobster.cmd.generate.oci_image: Contextual SBOM workflow finished successfully. 2026-03-10 19:57:32,602 [INFO] mobster.log: Contextual workflow completed in 3.11s 2026-03-10 19:57:32,611 [INFO] mobster.main: Exiting with code 0. [2026-03-10T19:57:32,668157677+00:00] End prepare-sboms pod: gh-test-custom-branch-otikki-on-push-4lbwx-build-container-pod | container step-upload-sbom: [2026-03-10T19:57:32,926026229+00:00] Upload SBOM INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' Using token for quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki Pushing sbom to registry Executing: cosign attach sbom --sbom sbom.json --type spdx quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki:e4e564e004482c0d4d791592992936f49b08bd49@sha256:1029ecbd4edf32cf788fa69530fc9758e1256e3ff245fc3b99db6b0de358b004 quay.io/redhat-appstudio-qe/build-e2e-mkep/gh-test-custom-branch-otikki@sha256:3bc89b53e800f5d68482fec34a16c06cdf82c676655080290f9b351273099ac5 [2026-03-10T19:57:36,000254356+00:00] End upload-sbom pod: gh-test-custom-branch-otikki-on-push-4lbwx-clair-scan-pod | init container: prepare 2026/03/10 19:57:47 Entrypoint initialization pod: gh-test-custom-branch-otikki-on-push-4lbwx-clair-scan-pod | init container: place-scripts