{"level":"info","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Operator Version: 0.0.1"} {"level":"info","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Go Version: go1.25.8 (Red Hat 1.25.8-1.module+el8.10.0+24168+9fd3a552) X:strictfipsruntime"} {"level":"info","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Go OS/Arch: linux/amd64"} {"level":"info","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Setting Up Manager"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Load KubeConfig"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Initialize Manager"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Initialize Scheme"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Getting Manager Options"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Adding Healthz and Readyz checks"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Registering Components"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Initialize Prometheus Registry"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Initialize Prometheus metrics endpoint","endpoint":"http://0.0.0.0:8383/metrics"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Initialize ConfigMap watcher"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Initialize Validation Engine"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Initialize Reconciler"} {"level":"info","ts":"2026-05-07T11:22:36Z","logger":"DeploymentValidation","msg":"Starting Manager"} {"level":"info","ts":"2026-05-07T11:22:36Z","msg":"starting server","name":"health probe","addr":"[::]:8081"} {"level":"info","ts":"2026-05-07T11:22:36Z","logger":"ConfigMapWatcher","msg":"a ConfigMap has been created under watched namespace","name":"deployment-validation-operator-config","namespace":"openshift-deployment-validation-operator"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"Current set of enabled checks","checks":"dangling-horizontalpodautoscaler, dangling-ingress, dangling-networkpolicy, dangling-networkpolicypeer-podselector, dangling-service, dangling-servicemonitor, dnsconfig-options, duplicate-env-var, env-value-from, host-ipc, host-network, host-pid, hpa-minimum-three-replicas, invalid-target-ports, job-ttl-seconds-after-finished, liveness-port, minimum-three-replicas, no-anti-affinity, no-node-affinity, non-existent-service-account, non-isolated-pod, pdb-max-unavailable, pdb-min-available, pdb-unhealthy-pod-eviction-policy, priority-class-name, privilege-escalation-container, privileged-container, readiness-port, restart-policy, run-as-non-root, scc-deny-privileged-container, schema-validation, sorted-keys, startup-port, unsafe-sysctls, unset-cpu-requirements, unset-memory-requirements"} {"level":"info","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"The ConfigMap has been updated"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:22:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:22:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:22:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:24:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:24:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:24:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:26:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:26:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:26:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:28:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:28:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:28:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:30:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:30:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:30:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:32:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:32:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:32:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager-operator","object":"cert-manager-operator-controller-manager","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager-operator","object":"cert-manager-operator-controller-manager","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager-operator","object":"cert-manager-operator-controller-manager","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"cert-manager-operator-controller-manager\" not found"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager-operator","object":"cert-manager-operator-controller-manager","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager-operator","object":"cert-manager-operator-controller-manager","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-operator\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager-operator","object":"cert-manager-operator-controller-manager-metrics-service","kind":"Service","validation":"dangling-service","check_description":"Indicates when services do not have any associated deployments.","check_remediation":"Confirm that your service's selector correctly matches the labels on one of your deployments.","check_failure_reason":"no pods found matching service labels (map[control-plane:controller-manager])"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager-operator","object":"cert-manager-operator-controller-manager-metrics-service","kind":"Service","validation":"dangling-service","check_description":"Indicates when services do not have any associated deployments.","check_remediation":"Confirm that your service's selector correctly matches the labels on one of your deployments.","check_failure_reason":"no pods found matching service labels (map[control-plane:controller-manager])"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"info","ts":"2026-05-07T11:32:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-infrastructure,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-infrastructure,helm.sh/chart=tsf-infrastructure-0.1.0"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"test-tpa-pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"test-keycloak-pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"tsf-infrastructure\" not found"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"copy-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"test-tpa-pgsql-bee\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"test-keycloak-pgsql-bee\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"test-rollout-openshift-pipelines\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"copy-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"test-tpa-pgsql-bee\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"test-keycloak-pgsql-bee\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"test-rollout-openshift-pipelines\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"copy-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"test-tpa-pgsql-bee\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"test-keycloak-pgsql-bee\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"test-tsf-infrastructure","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"test-rollout-openshift-pipelines\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/managed-by=Helm,helmet.redhat-appstudio.github.com/post-deploy=delete"} {"level":"info","ts":"2026-05-07T11:32:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"rhbk-operator","object":"rhbk-operator","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"rhbk-operator","object":"rhbk-operator","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"rhbk-operator","object":"rhbk-operator","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"rhbk-operator","object":"rhbk-operator","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"rhbk-operator\" not found"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"rhbk-operator","object":"rhbk-operator","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"rhbk-operator","object":"rhbk-operator","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"rhbk-operator\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:32:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:32:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:32:38.336123 1 request.go:752] "Waited before sending request" delay="1.517707126s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-keycloak/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MjIwMzksInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:32:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"info","ts":"2026-05-07T11:32:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:32:42Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-operator","object":"konflux-operator-controller-manager","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-operator","object":"konflux-operator-controller-manager","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-operator","object":"konflux-operator-controller-manager","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-operator","object":"konflux-operator-controller-manager","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"konflux-operator-controller-manager\" not found"} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-operator","object":"konflux-operator-controller-manager","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:32:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"info","ts":"2026-05-07T11:32:46Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:32:50.336057 1 request.go:752] "Waited before sending request" delay="1.995679613s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-tpa/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MjIzNDcsInN0YXJ0Ijoicmh0cGEtb3BlcmF0b3ItYmluZC1qb2JcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"rhtpa-operator-controller-manager","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"rhtpa-operator-controller-manager","kind":"Deployment","validation":"liveness-port","check_description":"Indicates when containers have a liveness probe to a not exposed port.","check_remediation":"Check which ports you've exposed and ensure they match what you have specified in the liveness probe.","check_failure_reason":"container \"manager\" does not expose port 8081 for the HTTPGet"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"rhtpa-operator-controller-manager","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"rhtpa-operator-controller-manager","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"rhtpa-operator-controller-manager","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"rhtpa-operator-controller-manager\" not found"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"rhtpa-operator-controller-manager","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"rhtpa-operator-controller-manager","kind":"Deployment","validation":"readiness-port","check_description":"Indicates when containers have a readiness probe to a not exposed port.","check_remediation":"Check which ports you've exposed and ensure they match what you have specified in the readiness probe.","check_failure_reason":"container \"manager\" does not expose port 8081 for the HTTPGet"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:32:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"info","ts":"2026-05-07T11:32:50Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:32:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:32:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:32:52Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:32:54Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"cli-server\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cli-server\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cli-server\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"cli-server\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cli-server\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cli-server\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"cli-server\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cli-server\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:32:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"trusted-artifact-signer","object":"cli-server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cli-server\" has memory limit 0"} {"level":"info","ts":"2026-05-07T11:32:56Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:33:00.337049 1 request.go:752] "Waited before sending request" delay="1.996670968s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/cert-manager/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MjI1NzIsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-controller\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-controller\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-controller\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-controller\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-cainjector\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-cainjector\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-cainjector\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-cainjector\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-webhook\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-webhook\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-webhook\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-webhook\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"cert-manager\" not found"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-controller\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-controller\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"cert-manager-cainjector\" not found"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-cainjector\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-cainjector","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-cainjector\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"cert-manager-webhook\" not found"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-webhook\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:33:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"cert-manager","object":"cert-manager-webhook","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"cert-manager-webhook\" has memory limit 0"} {"level":"info","ts":"2026-05-07T11:33:00Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:34:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":3,"labels":"batch.kubernetes.io/controller-uid=129fa865-cb51-4e02-92cd-5dac27f66ce8,batch.kubernetes.io/job-name=patch-tekton-config,controller-uid=129fa865-cb51-4e02-92cd-5dac27f66ce8,job-name=patch-tekton-config"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"patch-tekton-config","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"patch-tekton-config","kind":"Job","validation":"job-ttl-seconds-after-finished","check_description":"Indicates when standalone jobs do not set ttlSecondsAfterFinished and when jobs managed by cronjob do set ttlSecondsAfterFinished.","check_remediation":"Set Job.spec.ttlSecondsAfterFinished. Unset CronJob.Spec.JobTemplate.Spec.ttlSecondsAfterFinished.","check_failure_reason":"Standalone Job does not specify ttlSecondsAfterFinished"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"patch-tekton-config","kind":"Job","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"patch-tekton-config","kind":"Job","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"patch-tekton-config-sa\" not found"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"patch-tekton-config","kind":"Job","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"patch-tekton-config","kind":"Job","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"patch-tekton-config\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"patch-tekton-config","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"patch-tekton-config","kind":"Job","validation":"job-ttl-seconds-after-finished","check_description":"Indicates when standalone jobs do not set ttlSecondsAfterFinished and when jobs managed by cronjob do set ttlSecondsAfterFinished.","check_remediation":"Set Job.spec.ttlSecondsAfterFinished. Unset CronJob.Spec.JobTemplate.Spec.ttlSecondsAfterFinished.","check_failure_reason":"Standalone Job does not specify ttlSecondsAfterFinished"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"patch-tekton-config","kind":"Job","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"patch-tekton-config","kind":"Job","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"patch-tekton-config-sa\" not found"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"patch-tekton-config","kind":"Job","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"patch-tekton-config","kind":"Job","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"patch-tekton-config\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":3,"labels":"app.kubernetes.io/managed-by=Helm,helmet.redhat-appstudio.github.com/post-deploy=delete"} {"level":"info","ts":"2026-05-07T11:34:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:34:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-initial-admin\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-initial-admin\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"keycloak\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"keycloak\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-initial-admin\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-initial-admin\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"keycloak\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"keycloak\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-initial-admin\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-initial-admin\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"job-ttl-seconds-after-finished","check_description":"Indicates when standalone jobs do not set ttlSecondsAfterFinished and when jobs managed by cronjob do set ttlSecondsAfterFinished.","check_remediation":"Set Job.spec.ttlSecondsAfterFinished. Unset CronJob.Spec.JobTemplate.Spec.ttlSecondsAfterFinished.","check_failure_reason":"Standalone Job does not specify ttlSecondsAfterFinished"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"keycloak\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"keycloak\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"Service","validation":"dangling-service","check_description":"Indicates when services do not have any associated deployments.","check_remediation":"Confirm that your service's selector correctly matches the labels on one of your deployments.","check_failure_reason":"no pods found matching service labels (map[app:keycloak app.kubernetes.io/instance:keycloak app.kubernetes.io/managed-by:keycloak-operator])"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-initial-admin\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-initial-admin\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"keycloak\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak","kind":"StatefulSet","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"keycloak\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"keycloak-pgsql-bee","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-initial-admin\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"keycloak\" is referring to an unknown secret \"keycloak-initial-admin\""} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"job-ttl-seconds-after-finished","check_description":"Indicates when standalone jobs do not set ttlSecondsAfterFinished and when jobs managed by cronjob do set ttlSecondsAfterFinished.","check_remediation":"Set Job.spec.ttlSecondsAfterFinished. Unset CronJob.Spec.JobTemplate.Spec.ttlSecondsAfterFinished.","check_failure_reason":"Standalone Job does not specify ttlSecondsAfterFinished"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"keycloak\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-keycloak","object":"tsf-iam","kind":"Job","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"keycloak\" has cpu request 0"} {"level":"info","ts":"2026-05-07T11:34:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:34:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:34:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:34:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:34:38.338106 1 request.go:752] "Waited before sending request" delay="1.471666265s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-tpa/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MjQ4NDUsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"pgsql-bee\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"tpa-pgsql-bee","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:34:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:34:40Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:34:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:34:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:34:42Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:34:44Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:34:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:34:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:34:46Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:34:48.338444 1 request.go:752] "Waited before sending request" delay="1.896212387s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/cert-manager/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MjUyNDAsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMFx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:34:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:34:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:34:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:34:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:34:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:34:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:34:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:34:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:34:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:34:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:34:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:34:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:34:50Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:34:54Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"wait-for-trillian-db\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"wait-for-trillian-db\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logserver\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logserver\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logserver\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logserver\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logserver\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"liveness-port","check_description":"Indicates when containers have a liveness probe to a not exposed port.","check_remediation":"Check which ports you've exposed and ensure they match what you have specified in the liveness probe.","check_failure_reason":"container \"trillian-logserver\" does not expose port 8090 for the HTTPGet"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"readiness-port","check_description":"Indicates when containers have a readiness probe to a not exposed port.","check_remediation":"Check which ports you've exposed and ensure they match what you have specified in the readiness probe.","check_failure_reason":"container \"trillian-logserver\" does not expose port 8090 for the HTTPGet"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"wait-for-trillian-db\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"trillian-logserver\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"wait-for-trillian-db\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"trillian-logserver\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"wait-for-trillian-db\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"trillian-logserver\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"wait-for-trillian-db\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"wait-for-trillian-db\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logserver\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logserver\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logserver\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logserver\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logserver\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"liveness-port","check_description":"Indicates when containers have a liveness probe to a not exposed port.","check_remediation":"Check which ports you've exposed and ensure they match what you have specified in the liveness probe.","check_failure_reason":"container \"trillian-logserver\" does not expose port 8090 for the HTTPGet"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"readiness-port","check_description":"Indicates when containers have a readiness probe to a not exposed port.","check_remediation":"Check which ports you've exposed and ensure they match what you have specified in the readiness probe.","check_failure_reason":"container \"trillian-logserver\" does not expose port 8090 for the HTTPGet"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"wait-for-trillian-db\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"trillian-logserver\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"wait-for-trillian-db\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"trillian-logserver\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"wait-for-trillian-db\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logserver","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"trillian-logserver\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog-createtree-job-pgsqt","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog-createtree-job-pgsqt","kind":"Job","validation":"job-ttl-seconds-after-finished","check_description":"Indicates when standalone jobs do not set ttlSecondsAfterFinished and when jobs managed by cronjob do set ttlSecondsAfterFinished.","check_remediation":"Set Job.spec.ttlSecondsAfterFinished. Unset CronJob.Spec.JobTemplate.Spec.ttlSecondsAfterFinished.","check_failure_reason":"Standalone Job does not specify ttlSecondsAfterFinished"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog-createtree-job-pgsqt","kind":"Job","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog-createtree-job-pgsqt","kind":"Job","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog-createtree-job-pgsqt","kind":"Job","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"createtree\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog-createtree-job-pgsqt","kind":"Job","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"createtree\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog-createtree-job-pgsqt","kind":"Job","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"createtree\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"ctlog\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"ctlog\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"ctlog\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"ctlog\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"ctlog\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"ctlog\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"fulcio-server\" is referring to an unknown secret \"fulcio-cert-trusted-artifact-signer65nb6\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"fulcio\" not found"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"fulcio-server\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"fulcio-server\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"fulcio-server\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"fulcio-server\" is referring to an unknown secret \"fulcio-cert-trusted-artifact-signer65nb6\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"fulcio\" not found"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"fulcio-server\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"fulcio-server\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"fulcio-server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"fulcio-server\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"wait-for-trillian-db\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"wait-for-trillian-db\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logsigner\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logsigner\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logsigner\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logsigner\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logsigner\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"liveness-port","check_description":"Indicates when containers have a liveness probe to a not exposed port.","check_remediation":"Check which ports you've exposed and ensure they match what you have specified in the liveness probe.","check_failure_reason":"container \"trillian-logsigner\" does not expose port 8090 for the HTTPGet"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"readiness-port","check_description":"Indicates when containers have a readiness probe to a not exposed port.","check_remediation":"Check which ports you've exposed and ensure they match what you have specified in the readiness probe.","check_failure_reason":"container \"trillian-logsigner\" does not expose port 8090 for the HTTPGet"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"wait-for-trillian-db\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"trillian-logsigner\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"wait-for-trillian-db\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"trillian-logsigner\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"wait-for-trillian-db\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"trillian-logsigner\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"wait-for-trillian-db\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"wait-for-trillian-db\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"trillian-logsigner","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"trillian-logsigner\" is referring to an unknown secret \"trillian-db-connection-fc77t\""} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-createtree-job-cr87n","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:34:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:34:58Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:35:00.339085 1 request.go:752] "Waited before sending request" delay="1.894341806s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/cert-manager-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MjU1MjYsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbi1zZXJ2aWNlYWNjb3VudHMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:35:02Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:36:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:36:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:36:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:36:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"release-service","object":"release-service-controller-manager","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"release-service","object":"release-service-controller-manager","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"release-service","object":"release-service-controller-manager","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"release-service","object":"release-service-controller-manager","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-service-controller-manager\" not found"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"release-service","object":"release-service-controller-manager","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"release-service","object":"release-service-webhook-service","kind":"Service","validation":"dangling-service","check_description":"Indicates when services do not have any associated deployments.","check_remediation":"Confirm that your service's selector correctly matches the labels on one of your deployments.","check_failure_reason":"no pods found matching service labels (map[control-plane:controller-manager])"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T11:36:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"rekor-server\" is referring to an unknown secret \"redis-password-trusted-artifact-signerkznpv\""} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"rekor\" not found"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"rekor-server\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"rekor-server\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"rekor-server\" is referring to an unknown secret \"redis-password-trusted-artifact-signerkznpv\""} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"rekor\" not found"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"rekor-server\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"rekor-server\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"ctlog\" not found"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"ctlog\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"ctlog\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"ctlog","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"ctlog\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"rekor-redis\" is referring to an unknown secret \"redis-password-trusted-artifact-signerkznpv\""} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"enable-tls\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"rekor-redis\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"enable-tls\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"rekor-redis\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"enable-tls\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"rekor-redis\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"rekor-redis\" is referring to an unknown secret \"redis-password-trusted-artifact-signerkznpv\""} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"enable-tls\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"rekor-redis\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"enable-tls\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"rekor-redis\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"enable-tls\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"rekor-redis\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-search-ui","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-search-ui","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-search-ui","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-search-ui","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"rekor-ui\" not found"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-search-ui","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-search-ui","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"rekor-search-ui\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-search-ui","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"rekor-search-ui\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-search-ui","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"rekor-search-ui\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"job-ttl-seconds-after-finished","check_description":"Indicates when standalone jobs do not set ttlSecondsAfterFinished and when jobs managed by cronjob do set ttlSecondsAfterFinished.","check_remediation":"Set Job.spec.ttlSecondsAfterFinished. Unset CronJob.Spec.JobTemplate.Spec.ttlSecondsAfterFinished.","check_failure_reason":"Standalone Job does not specify ttlSecondsAfterFinished"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"tuf-repository-init\" not found"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"tuf-init\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"tuf-init\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"tuf-server\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"tuf-server\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"tuf-server\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"tuf-server\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"rekor-server\" is referring to an unknown secret \"redis-password-trusted-artifact-signerkznpv\""} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"rekor\" not found"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"rekor-server\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"rekor-server\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"job-ttl-seconds-after-finished","check_description":"Indicates when standalone jobs do not set ttlSecondsAfterFinished and when jobs managed by cronjob do set ttlSecondsAfterFinished.","check_remediation":"Set Job.spec.ttlSecondsAfterFinished. Unset CronJob.Spec.JobTemplate.Spec.ttlSecondsAfterFinished.","check_failure_reason":"Standalone Job does not specify ttlSecondsAfterFinished"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"tuf-repository-init\" not found"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"tuf-init\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"tuf-repository-init-hpwgw","kind":"Job","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"tuf-init\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"rekor-redis\" is referring to an unknown secret \"redis-password-trusted-artifact-signerkznpv\""} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tas","object":"rekor-redis","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:36:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T11:36:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:36:38.361169 1 request.go:752] "Waited before sending request" delay="1.371657552s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/cert-manager-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6Mjg1OTgsInN0YXJ0IjoicGlwZWxpbmVzLXNjYy1yb2xlYmluZGluZ1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:36:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:36:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-controller-manager","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-controller-manager","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-controller-manager","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-controller-manager","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"image-controller-controller-manager\" not found"} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-controller-manager","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-image-pruner-cronjob","kind":"CronJob","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-image-pruner-cronjob","kind":"CronJob","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"image-pruner\" is referring to an unknown secret \"quaytoken\""} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-image-pruner-cronjob","kind":"CronJob","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"image-pruner\" is referring to an unknown secret \"quaytoken\""} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-image-pruner-cronjob","kind":"CronJob","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-image-pruner-cronjob","kind":"CronJob","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-notification-resetter-cronjob","kind":"CronJob","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-notification-resetter-cronjob","kind":"CronJob","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"notification-resetter\" is referring to an unknown secret \"quaytoken\""} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-notification-resetter-cronjob","kind":"CronJob","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"notification-resetter\" is referring to an unknown secret \"quaytoken\""} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-notification-resetter-cronjob","kind":"CronJob","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:42Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"image-controller","object":"image-controller-notification-resetter-cronjob","kind":"CronJob","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"info","ts":"2026-05-07T11:36:42Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:36:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T11:36:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"build-service","object":"build-service-controller-manager","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"build-service","object":"build-service-controller-manager","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:36:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"build-service","object":"build-service-controller-manager","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"build-service","object":"build-service-controller-manager","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-service-controller-manager\" not found"} {"level":"debug","ts":"2026-05-07T11:36:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"build-service","object":"build-service-controller-manager","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:36:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:36:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:36:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:36:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"info","ts":"2026-05-07T11:36:46Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:36:48.361318 1 request.go:752] "Waited before sending request" delay="1.899348529s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/enterprise-contract-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6Mjg3MDQsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:36:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"info","ts":"2026-05-07T11:36:50Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:36:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"info","ts":"2026-05-07T11:36:54Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:36:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T11:36:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"segment-bridge","object":"segment-bridge","kind":"CronJob","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:36:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"segment-bridge","object":"segment-bridge","kind":"CronJob","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:36:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"segment-bridge","object":"segment-bridge","kind":"CronJob","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"info","ts":"2026-05-07T11:36:56Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:37:00.361700 1 request.go:752] "Waited before sending request" delay="1.995495271s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6Mjg4MzYsInN0YXJ0Ijoic3lzdGVtOmltYWdlLXB1bGxlcnNcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"job-ttl-seconds-after-finished","check_description":"Indicates when standalone jobs do not set ttlSecondsAfterFinished and when jobs managed by cronjob do set ttlSecondsAfterFinished.","check_remediation":"Set Job.spec.ttlSecondsAfterFinished. Unset CronJob.Spec.JobTemplate.Spec.ttlSecondsAfterFinished.","check_failure_reason":"Standalone Job does not specify ttlSecondsAfterFinished"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"tsf-pipelines\" not found"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"tekton-chains-cosign\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"tekton-chains-cosign\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"tekton-chains-cosign\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/managed-by=Helm,helmet.redhat-appstudio.github.com/post-deploy=delete"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"job-ttl-seconds-after-finished","check_description":"Indicates when standalone jobs do not set ttlSecondsAfterFinished and when jobs managed by cronjob do set ttlSecondsAfterFinished.","check_remediation":"Set Job.spec.ttlSecondsAfterFinished. Unset CronJob.Spec.JobTemplate.Spec.ttlSecondsAfterFinished.","check_failure_reason":"Standalone Job does not specify ttlSecondsAfterFinished"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"tsf-pipelines\" not found"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"tekton-chains-cosign\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"tekton-chains-cosign\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:37:00Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf","object":"tsf-tekton-configuration","kind":"Job","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"tekton-chains-cosign\" has memory limit 0"} {"level":"info","ts":"2026-05-07T11:37:00Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:37:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:37:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:37:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:37:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:37:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:37:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:37:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:37:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:37:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:37:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:37:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:37:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:37:04Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:37:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T11:37:08Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"namespace-lister","object":"namespace-lister","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"namespace-lister","object":"namespace-lister","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"namespace-lister","object":"namespace-lister","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"namespace-lister","object":"namespace-lister","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"namespace-lister\" not found"} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"namespace-lister","object":"namespace-lister-allow-from-konfluxui","kind":"NetworkPolicy","validation":"dangling-networkpolicypeer-podselector","check_description":"Indicates when NetworkPolicyPeer in Egress/Ingress rules -in the Spec of NetworkPolicy- do not have any associated deployments. Applied on peer specified with podSelectors only.","check_remediation":"Confirm that your NetworkPolicy's Ingress/Egress peer's podselector correctly matches the labels on one of your deployments.","check_failure_reason":"no pods found matching networkpolicy rule's podSelector labels (app=proxy)"} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"namespace-lister","object":"namespace-lister","kind":"Service","validation":"dangling-service","check_description":"Indicates when services do not have any associated deployments.","check_remediation":"Confirm that your service's selector correctly matches the labels on one of your deployments.","check_failure_reason":"no pods found matching service labels (map[apps:namespace-lister])"} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"namespace-lister","object":"namespace-lister-allow-from-konfluxui","kind":"NetworkPolicy","validation":"dangling-networkpolicy","check_description":"Indicates when networkpolicies do not have any associated deployments.","check_remediation":"Confirm that your networkPolicy's podselector correctly matches the labels on one of your deployments.","check_failure_reason":"no pods found matching networkpolicy's podSelector labels ({map[apps:namespace-lister] []}) "} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"namespace-lister","object":"namespace-lister-allow-from-konfluxui","kind":"NetworkPolicy","validation":"dangling-networkpolicypeer-podselector","check_description":"Indicates when NetworkPolicyPeer in Egress/Ingress rules -in the Spec of NetworkPolicy- do not have any associated deployments. Applied on peer specified with podSelectors only.","check_remediation":"Confirm that your NetworkPolicy's Ingress/Egress peer's podselector correctly matches the labels on one of your deployments.","check_failure_reason":"no pods found matching networkpolicy rule's podSelector labels (app=proxy)"} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"namespace-lister","object":"namespace-lister-allow-to-apiserver","kind":"NetworkPolicy","validation":"dangling-networkpolicy","check_description":"Indicates when networkpolicies do not have any associated deployments.","check_remediation":"Confirm that your networkPolicy's podselector correctly matches the labels on one of your deployments.","check_failure_reason":"no pods found matching networkpolicy's podSelector labels ({map[apps:namespace-lister] []}) "} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:37:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T11:37:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:37:12.361221 1 request.go:752] "Waited before sending request" delay="1.882932272s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-ui/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MjkwMTUsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Service","validation":"dangling-service","check_description":"Indicates when services do not have any associated deployments.","check_remediation":"Confirm that your service's selector correctly matches the labels on one of your deployments.","check_failure_reason":"no pods found matching service labels (map[app:dex])"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"konflux-ui","kind":"Ingress","validation":"dangling-ingress","check_description":"Indicates when ingress do not have any associated services.","check_remediation":"Confirm that your ingress's backend correctly matches the name and port on one of your services.","check_failure_reason":"no service found matching ingress label (proxy), port web-tls"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"oauth2-proxy\" is referring to an unknown secret \"oauth2-proxy-client-secret\""} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"oauth2-proxy\" is referring to an unknown secret \"oauth2-proxy-cookie-secret\""} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"proxy\" not found"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"oauth2-proxy\" is referring to an unknown secret \"oauth2-proxy-client-secret\""} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"oauth2-proxy\" is referring to an unknown secret \"oauth2-proxy-cookie-secret\""} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"proxy\" not found"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"dex\" is referring to an unknown secret \"dex-client\""} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"dex\" is referring to an unknown secret \"oauth2-proxy-client-secret\""} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"dex\" is referring to an unknown secret \"dex-client\""} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"dex\" is referring to an unknown secret \"oauth2-proxy-client-secret\""} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"dex\" is referring to an unknown secret \"dex-client\""} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"dex\" is referring to an unknown secret \"oauth2-proxy-client-secret\""} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"dex\" not found"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"dex","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"oauth2-proxy\" is referring to an unknown secret \"oauth2-proxy-client-secret\""} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"oauth2-proxy\" is referring to an unknown secret \"oauth2-proxy-cookie-secret\""} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"proxy\" not found"} {"level":"debug","ts":"2026-05-07T11:37:14Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"konflux-ui","object":"proxy","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"info","ts":"2026-05-07T11:37:14Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:37:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"info","ts":"2026-05-07T11:37:18Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-controller-manager","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-controller-manager","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-controller-manager","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-controller-manager","kind":"Deployment","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"integration-service-controller-manager\" not found"} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-controller-manager","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-snapshot-garbage-collector","kind":"CronJob","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-snapshot-garbage-collector","kind":"CronJob","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-snapshot-garbage-collector","kind":"CronJob","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-snapshot-garbage-collector","kind":"CronJob","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:37:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"info","ts":"2026-05-07T11:37:22Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:37:24.361545 1 request.go:752] "Waited before sending request" delay="1.893940384s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MjkyMTIsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:37:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:37:26Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:37:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"info","ts":"2026-05-07T11:37:30Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=create-db,batch.kubernetes.io/controller-uid=cf807ea5-2dfb-42fe-b9c8-e07c359e64fe,batch.kubernetes.io/job-name=create-db,controller-uid=cf807ea5-2dfb-42fe-b9c8-e07c359e64fe,job-name=create-db"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"job\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"job\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-db","kind":"Job","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"job\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=create-importers,batch.kubernetes.io/controller-uid=9d0240fc-796a-4026-b3bb-d924d0392b2b,batch.kubernetes.io/job-name=create-importers,controller-uid=9d0240fc-796a-4026-b3bb-d924d0392b2b,job-name=create-importers"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-importers","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-importers","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-importers","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-importers","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-importers","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-importers","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-importers","kind":"Job","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-importers","kind":"Job","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-importers","kind":"Job","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"job\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-importers","kind":"Job","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"job\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"create-importers","kind":"Job","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"job\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=migrate-db,batch.kubernetes.io/controller-uid=5d871da5-6a6f-4068-bba6-bcad897411d6,batch.kubernetes.io/job-name=migrate-db,controller-uid=5d871da5-6a6f-4068-bba6-bcad897411d6,job-name=migrate-db"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"migrate-db","kind":"Job","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"migrate-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"migrate-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"migrate-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"migrate-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"migrate-db","kind":"Job","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"job\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"migrate-db","kind":"Job","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"migrate-db","kind":"Job","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"migrate-db","kind":"Job","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"job\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"migrate-db","kind":"Job","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"job\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"migrate-db","kind":"Job","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"job\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=create-db,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=create-importers,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=migrate-db,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:37:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:37:34Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:37:36.360451 1 request.go:752] "Waited before sending request" delay="1.881777212s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MjkzNjksInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:37:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:37:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:37:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:37:38Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:38:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=migrate-db,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=migrate-db,batch.kubernetes.io/controller-uid=5d871da5-6a6f-4068-bba6-bcad897411d6,batch.kubernetes.io/job-name=migrate-db,controller-uid=5d871da5-6a6f-4068-bba6-bcad897411d6,job-name=migrate-db"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=create-db,batch.kubernetes.io/controller-uid=cf807ea5-2dfb-42fe-b9c8-e07c359e64fe,batch.kubernetes.io/job-name=create-db,controller-uid=cf807ea5-2dfb-42fe-b9c8-e07c359e64fe,job-name=create-db"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=create-db,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=create-importers,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=create-importers,batch.kubernetes.io/controller-uid=9d0240fc-796a-4026-b3bb-d924d0392b2b,batch.kubernetes.io/job-name=create-importers,controller-uid=9d0240fc-796a-4026-b3bb-d924d0392b2b,job-name=create-importers"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:38:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:38:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:38:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:38:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:38:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:38:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:38:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:38:38.374390 1 request.go:752] "Waited before sending request" delay="1.435853816s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/release-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzAwODcsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:38:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:38:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:38:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:38:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:38:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T11:38:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:38:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:38:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T11:38:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:38:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T11:38:42Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:38:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:38:46Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:38:50.375336 1 request.go:752] "Waited before sending request" delay="1.995897834s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/image-controller/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzAxOTgsInN0YXJ0Ijoic3lzdGVtOmltYWdlLWJ1aWxkZXJzXHUwMDAwIn0&limit=5" {"level":"debug","ts":"2026-05-07T11:38:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T11:38:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:38:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:38:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:38:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:38:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:38:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:38:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T11:38:50Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:38:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:38:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:38:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:38:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:38:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:38:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:38:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T11:38:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T11:38:54Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:38:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T11:38:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T11:38:58Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:39:00.375371 1 request.go:752] "Waited before sending request" delay="1.903099256s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-cli/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzAzMzMsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:39:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T11:39:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T11:39:02Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:39:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T11:39:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T11:39:04Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:39:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T11:39:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T11:39:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T11:39:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T11:39:06Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:39:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:39:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:39:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:39:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:39:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:39:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:39:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:39:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:39:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:39:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:39:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:39:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:39:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:39:12.374772 1 request.go:752] "Waited before sending request" delay="1.894947989s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-keycloak/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzA0NjIsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:39:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T11:39:14Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:39:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T11:39:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:39:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:39:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:39:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:39:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T11:39:16Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:39:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:39:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:39:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:39:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:39:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:39:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:39:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T11:39:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:39:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T11:39:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:39:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T11:39:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T11:39:20Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:39:24.374147 1 request.go:752] "Waited before sending request" delay="1.99421435s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/default-tenant/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzA1NzcsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:39:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T11:39:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"info","ts":"2026-05-07T11:39:24Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:39:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T11:39:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:39:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:39:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:39:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:39:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:39:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:39:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:39:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T11:39:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T11:39:28Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:39:32Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:39:34.375052 1 request.go:752] "Waited before sending request" delay="1.899869837s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzA3MTIsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:39:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:39:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:39:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T11:39:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T11:39:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:40:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T11:40:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:40:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T11:40:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T11:40:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T11:40:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T11:40:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:40:38.427853 1 request.go:752] "Waited before sending request" delay="1.492551611s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-cli/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzE0ODEsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:40:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T11:40:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T11:40:40Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:40:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T11:40:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T11:40:42Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:40:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T11:40:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T11:40:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T11:40:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T11:40:44Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:40:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:40:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:40:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:40:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:40:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:40:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:40:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:40:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:40:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:40:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:40:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:40:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:40:48Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:40:50.427441 1 request.go:752] "Waited before sending request" delay="1.898035939s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-keycloak/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzE2MTEsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:40:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T11:40:52Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:40:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:40:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:40:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:40:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:40:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T11:40:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T11:40:54Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:40:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:40:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:40:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T11:40:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:40:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T11:40:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:40:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T11:40:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:40:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:40:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:40:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:40:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T11:40:58Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:41:00.428059 1 request.go:752] "Waited before sending request" delay="1.907994495s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/default-tenant/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzE3MjAsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:41:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T11:41:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"info","ts":"2026-05-07T11:41:02Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:41:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T11:41:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:41:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:41:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:41:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:41:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:41:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:41:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:41:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T11:41:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T11:41:06Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:41:10.429121 1 request.go:752] "Waited before sending request" delay="1.996243577s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/managed-tenant-oafxv/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzE4MTMsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"info","ts":"2026-05-07T11:41:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:41:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:41:14Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:41:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T11:41:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T11:41:18Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:41:22.428234 1 request.go:752] "Waited before sending request" delay="1.994725654s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-tpa/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzE5NDIsInN0YXJ0Ijoicmh0cGEtb3BlcmF0b3ItYmluZC1qb2JcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=create-db,batch.kubernetes.io/controller-uid=cf807ea5-2dfb-42fe-b9c8-e07c359e64fe,batch.kubernetes.io/job-name=create-db,controller-uid=cf807ea5-2dfb-42fe-b9c8-e07c359e64fe,job-name=create-db"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=migrate-db,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=migrate-db,batch.kubernetes.io/controller-uid=5d871da5-6a6f-4068-bba6-bcad897411d6,batch.kubernetes.io/job-name=migrate-db,controller-uid=5d871da5-6a6f-4068-bba6-bcad897411d6,job-name=migrate-db"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=create-db,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=create-importers,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=create-importers,batch.kubernetes.io/controller-uid=9d0240fc-796a-4026-b3bb-d924d0392b2b,batch.kubernetes.io/job-name=create-importers,controller-uid=9d0240fc-796a-4026-b3bb-d924d0392b2b,job-name=create-importers"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:41:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:41:22Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:41:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:41:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:41:24Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:41:26Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:41:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:41:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:41:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:41:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:41:28Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:41:32.428295 1 request.go:752] "Waited before sending request" delay="1.990043281s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/cert-manager/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzIwNjMsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:41:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:41:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:41:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:41:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:41:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:41:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:41:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:41:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:41:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:41:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:41:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:41:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:41:32Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:41:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:41:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:41:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:41:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:41:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:41:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T11:41:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:41:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:41:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T11:41:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:42:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T11:42:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"info","ts":"2026-05-07T11:42:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T11:42:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:42:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:42:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:42:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:42:38.366051 1 request.go:752] "Waited before sending request" delay="1.529948535s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-info/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzI4NTUsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:42:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T11:42:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T11:42:40Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=create-importers,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=migrate-db,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=create-importers,batch.kubernetes.io/controller-uid=9d0240fc-796a-4026-b3bb-d924d0392b2b,batch.kubernetes.io/job-name=create-importers,controller-uid=9d0240fc-796a-4026-b3bb-d924d0392b2b,job-name=create-importers"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=create-db,batch.kubernetes.io/controller-uid=cf807ea5-2dfb-42fe-b9c8-e07c359e64fe,batch.kubernetes.io/job-name=create-db,controller-uid=cf807ea5-2dfb-42fe-b9c8-e07c359e64fe,job-name=create-db"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=create-db,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=database,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=migrate-db,batch.kubernetes.io/controller-uid=5d871da5-6a6f-4068-bba6-bcad897411d6,batch.kubernetes.io/job-name=migrate-db,controller-uid=5d871da5-6a6f-4068-bba6-bcad897411d6,job-name=migrate-db"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:42:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:42:44Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:42:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:42:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:42:46Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:42:48Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:42:50.366576 1 request.go:752] "Waited before sending request" delay="1.908384783s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/trusted-artifact-signer/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzI5ODUsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:42:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:42:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:42:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:42:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:42:50Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:42:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:42:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:42:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:42:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:42:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:42:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:42:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:42:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:42:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:42:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:42:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:42:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:42:54Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:42:58Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:43:00.366620 1 request.go:752] "Waited before sending request" delay="1.898670566s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/release-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzMwOTYsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:43:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T11:43:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:43:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:43:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:43:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:43:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:43:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:43:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T11:43:02Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:43:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T11:43:06Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:43:10.367469 1 request.go:752] "Waited before sending request" delay="1.996654937s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/cert-manager-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzMxOTAsInN0YXJ0IjoicGlwZWxpbmVzLXNjYy1yb2xlYmluZGluZ1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:43:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:43:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:43:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:43:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:43:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:43:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:43:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T11:43:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:43:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:43:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T11:43:14Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:43:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T11:43:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:43:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:43:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:43:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:43:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:43:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:43:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T11:43:18Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:43:22.366995 1 request.go:752] "Waited before sending request" delay="1.995048s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/enterprise-contract-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzMzMjcsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:43:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T11:43:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T11:43:22Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:43:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T11:43:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T11:43:26Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:43:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T11:43:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T11:43:28Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:43:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T11:43:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T11:43:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T11:43:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T11:43:30Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:43:34.366034 1 request.go:752] "Waited before sending request" delay="1.995185449s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/rhbk-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzM0NjAsInN0YXJ0Ijoicmhiay1vcGVyYXRvci52MjYuNC4xMS1vcHIuMlx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:43:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:43:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:43:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:43:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:43:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:43:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:43:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:43:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:43:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:43:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:43:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:43:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:43:34Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:43:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T11:43:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:43:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T11:43:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:43:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:43:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:43:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:43:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T11:43:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:44:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:44:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:44:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:44:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:44:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T11:44:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:44:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T11:44:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:44:38.348078 1 request.go:752] "Waited before sending request" delay="1.3511763s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/cert-manager-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzQyMzgsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbi1zZXJ2aWNlYWNjb3VudHMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:44:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:44:40Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:44:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:44:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:44:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:44:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:44:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T11:44:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:44:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:44:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T11:44:44Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:44:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:44:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:44:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:44:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:44:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T11:44:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:44:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:44:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T11:44:48Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:44:50.349169 1 request.go:752] "Waited before sending request" delay="1.909186477s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/enterprise-contract-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzQzNTksInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:44:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T11:44:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T11:44:52Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:44:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T11:44:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T11:44:56Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:44:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T11:44:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T11:44:58Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:45:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T11:45:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T11:45:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T11:45:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T11:45:00Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:45:02.348393 1 request.go:752] "Waited before sending request" delay="1.903952501s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/rhbk-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzQ0OTcsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:45:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:45:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:45:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:45:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:45:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:45:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:45:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:45:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:45:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:45:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:45:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:45:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:45:04Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:45:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T11:45:08Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:45:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T11:45:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:45:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:45:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:45:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:45:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T11:45:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:45:14.349357 1 request.go:752] "Waited before sending request" delay="1.994046673s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-ui/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzQ2MTAsInN0YXJ0Ijoic3lzdGVtOmltYWdlLWJ1aWxkZXJzXHUwMDAwIn0&limit=5" {"level":"debug","ts":"2026-05-07T11:45:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T11:45:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:45:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:45:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:45:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:45:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:45:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:45:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:45:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T11:45:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:45:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T11:45:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T11:45:14Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:45:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T11:45:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"info","ts":"2026-05-07T11:45:18Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:45:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T11:45:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:45:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:45:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:45:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:45:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:45:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:45:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:45:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T11:45:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T11:45:22Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:45:26.348935 1 request.go:752] "Waited before sending request" delay="1.994043883s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/managed-tenant-oafxv/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzQ3NTEsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"info","ts":"2026-05-07T11:45:26Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:45:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:45:30Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:45:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T11:45:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T11:45:34Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:45:38.347587 1 request.go:752] "Waited before sending request" delay="1.989300331s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-tpa/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzQ5MDAsInN0YXJ0Ijoicmh0cGEtb3BlcmF0b3ItYmluZC1qb2JcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:45:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:45:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:45:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:45:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:45:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:46:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:46:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T11:46:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T11:46:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:46:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:46:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T11:46:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:46:38.344829 1 request.go:752] "Waited before sending request" delay="1.44953313s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/build-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzU2MTgsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMFx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:46:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T11:46:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:46:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:46:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:46:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:46:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:46:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:46:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T11:46:40Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:46:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T11:46:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T11:46:44Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:46:48.344898 1 request.go:752] "Waited before sending request" delay="1.993612866s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-cli/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzU3MDAsInN0YXJ0Ijoic3lzdGVtOmltYWdlLWJ1aWxkZXJzXHUwMDAwIn0&limit=5" {"level":"debug","ts":"2026-05-07T11:46:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T11:46:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T11:46:48Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:46:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T11:46:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T11:46:50Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:46:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T11:46:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T11:46:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T11:46:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T11:46:52Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:46:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:46:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:46:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:46:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:46:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:46:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:46:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:46:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:46:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:46:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:46:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:46:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:46:56Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:46:58.345041 1 request.go:752] "Waited before sending request" delay="1.893505244s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-keycloak/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzU4NDMsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:47:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T11:47:00Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:47:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T11:47:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:47:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:47:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:47:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:47:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T11:47:02Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:47:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T11:47:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:47:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T11:47:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:47:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T11:47:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:47:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:47:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:47:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:47:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:47:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:47:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T11:47:06Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:47:10.345446 1 request.go:752] "Waited before sending request" delay="1.995391203s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/default-tenant/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzU5NTgsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:47:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T11:47:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"info","ts":"2026-05-07T11:47:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:47:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T11:47:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:47:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:47:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:47:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:47:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:47:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:47:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:47:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T11:47:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T11:47:14Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:47:18Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:47:22.346176 1 request.go:752] "Waited before sending request" delay="1.99504665s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzYwODYsInN0YXJ0IjoicGlwZWxpbmVzLXNjYy1yb2xlYmluZGluZ1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:47:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:47:22Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:47:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T11:47:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T11:47:26Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:47:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:47:30Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:47:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:47:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:47:32Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:47:34.345047 1 request.go:752] "Waited before sending request" delay="1.905105928s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/open-cluster-management-agent-addon/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzYyNDMsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"info","ts":"2026-05-07T11:47:34Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:47:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:47:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:47:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:47:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:47:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:47:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:48:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T11:48:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:48:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T11:48:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T11:48:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T11:48:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T11:48:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:48:38.430036 1 request.go:752] "Waited before sending request" delay="1.538384065s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-cli/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzY5ODQsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:48:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T11:48:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T11:48:40Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:48:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T11:48:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T11:48:42Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:48:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T11:48:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T11:48:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T11:48:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T11:48:44Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:48:48.430859 1 request.go:752] "Waited before sending request" delay="1.99520785s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/rhbk-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzcwNjYsInN0YXJ0Ijoicmhiay1vcGVyYXRvci52MjYuNC4xMS1vcHIuMlx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:48:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:48:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:48:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:48:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:48:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:48:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:48:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:48:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:48:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:48:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:48:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:48:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:48:48Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:48:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T11:48:52Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:48:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:48:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:48:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T11:48:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:48:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:48:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T11:48:54Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:48:58.430934 1 request.go:752] "Waited before sending request" delay="1.994164356s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-ui/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzcxNzgsInN0YXJ0Ijoic3lzdGVtOmltYWdlLWJ1aWxkZXJzXHUwMDAwIn0&limit=5" {"level":"debug","ts":"2026-05-07T11:48:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:48:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:48:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T11:48:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:48:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T11:48:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:48:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T11:48:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:48:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:48:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:48:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:48:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T11:48:58Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:49:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T11:49:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"info","ts":"2026-05-07T11:49:02Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:49:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T11:49:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:49:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T11:49:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:49:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:49:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:49:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:49:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:49:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:49:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T11:49:06Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:49:10.431541 1 request.go:752] "Waited before sending request" delay="1.99615669s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/managed-tenant-oafxv/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzczMjAsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"info","ts":"2026-05-07T11:49:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:49:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:49:14Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:49:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T11:49:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T11:49:18Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:49:22.431052 1 request.go:752] "Waited before sending request" delay="1.993053038s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-tpa/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6Mzc0NTMsInN0YXJ0Ijoicmh0cGEtb3BlcmF0b3ItYmluZC1qb2JcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:49:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:49:22Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:49:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:49:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:49:24Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:49:26Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:49:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:49:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:49:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:49:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:49:28Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:49:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:49:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:49:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:49:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:49:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:49:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:49:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:49:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:49:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:49:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:49:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:49:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:49:32Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:49:34.430032 1 request.go:752] "Waited before sending request" delay="1.901105557s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/rhtpa-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6Mzc4ODMsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"info","ts":"2026-05-07T11:49:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:49:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:49:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:49:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T11:49:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:49:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:49:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:49:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:49:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T11:49:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:50:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:50:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T11:50:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T11:50:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T11:50:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T11:50:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T11:50:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:50:38.361141 1 request.go:752] "Waited before sending request" delay="1.484820097s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/segment-bridge/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6Mzg3OTYsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:50:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T11:50:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T11:50:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:50:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T11:50:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T11:50:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T11:50:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T11:50:40Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:50:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:50:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:50:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:50:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:50:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:50:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:50:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:50:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:50:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:50:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:50:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:50:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:50:44Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:50:48.361314 1 request.go:752] "Waited before sending request" delay="1.99159235s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-keycloak/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6Mzg5MzAsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:50:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T11:50:48Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:50:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T11:50:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:50:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:50:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:50:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:50:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T11:50:50Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:50:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:50:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:50:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T11:50:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:50:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T11:50:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:50:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T11:50:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:50:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:50:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:50:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:50:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T11:50:54Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:50:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T11:50:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=true,pipelinesascode.tekton.dev/check-run-id=74808955078,pipelinesascode.tekton.dev/event-type=pull_request,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-pull-request,pipelinesascode.tekton.dev/pull-request=373,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=e4757a8746f7f6293b53f5f5c6e099e62044d6ed,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-pull-request-p7bcf,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-pull-request-p7bcf,tekton.dev/pipelineRunUID=efedc9d9-0221-4992-8394-15a1de055139,tekton.dev/pipelineTask=init,tekton.dev/task=init,tekton.dev/taskRun=tsf-comp-6vc6m-on-pull-request-p7bcf-init,tekton.dev/taskRunUID=c37f832e-4535-4563-a40f-0c2578a4c4be,test.appstudio.openshift.io/pr-group-sha=e2dc7155736f322e513d7b17ede1d4f575050953a9e50fc31b25206a51fcd3"} {"level":"debug","ts":"2026-05-07T11:50:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-pull-request-p7bcf-init-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:50:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-pull-request-p7bcf-init-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:50:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-pull-request-p7bcf-init-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:50:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-pull-request-p7bcf-init-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:50:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-pull-request-p7bcf-init-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:50:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-pull-request-p7bcf-init-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:50:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-pull-request-p7bcf-init-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-init\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:50:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-pull-request-p7bcf-init-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:50:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-pull-request-p7bcf-init-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"info","ts":"2026-05-07T11:50:58Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:51:00.361052 1 request.go:752] "Waited before sending request" delay="1.883227878s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/integration-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzkyMDksInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:51:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:51:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:51:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:51:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:51:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T11:51:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:51:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T11:51:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:51:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:51:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T11:51:02Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:51:06Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:51:10.361058 1 request.go:752] "Waited before sending request" delay="1.994483649s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6MzkzNTMsInN0YXJ0IjoicGlwZWxpbmVzLXNjYy1yb2xlYmluZGluZ1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:51:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:51:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:51:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T11:51:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T11:51:14Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:51:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:51:18Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:51:20.361828 1 request.go:752] "Waited before sending request" delay="1.832277457s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6Mzk1NTAsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:51:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:51:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:51:20Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:51:22Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:51:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:51:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:51:24Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:51:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:51:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:51:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:51:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:51:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:51:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:51:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:51:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:51:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:51:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:51:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:51:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:51:28Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:51:32.362427 1 request.go:752] "Waited before sending request" delay="1.9960513s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/rhtpa-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6Mzk3MDcsInN0YXJ0Ijoic3lzdGVtOmltYWdlLWJ1aWxkZXJzXHUwMDAwIn0&limit=5" {"level":"info","ts":"2026-05-07T11:51:32Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:51:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T11:51:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:51:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:51:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:51:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:51:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:51:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:51:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T11:51:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T11:51:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:52:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:52:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T11:52:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:52:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:52:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:52:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:52:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:52:38.361080 1 request.go:752] "Waited before sending request" delay="1.37719947s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/cert-manager/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDA1OTIsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:52:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:52:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:52:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:52:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:52:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:52:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:52:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:52:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:52:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:52:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:52:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:52:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:52:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:52:42Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:52:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T11:52:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:52:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:52:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:52:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:52:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:52:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:52:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T11:52:46Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:52:50.362047 1 request.go:752] "Waited before sending request" delay="1.995715469s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-tas/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDA3NTgsInN0YXJ0IjoicmVrb3ItY3JlYXRldHJlZS1qb2JcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:52:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T11:52:50Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:52:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:52:54Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:52:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T11:52:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:52:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:52:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:52:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:52:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:52:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:52:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T11:52:58Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:53:02.362051 1 request.go:752] "Waited before sending request" delay="1.995659351s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/build-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDA4ODgsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:53:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:53:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:53:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:53:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:53:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T11:53:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:53:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:53:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T11:53:02Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:53:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T11:53:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T11:53:06Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:53:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T11:53:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T11:53:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:53:12.362053 1 request.go:752] "Waited before sending request" delay="1.895776851s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/segment-bridge/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDEwMzMsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:53:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T11:53:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T11:53:12Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:53:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T11:53:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T11:53:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T11:53:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T11:53:14Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:53:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:53:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:53:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:53:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:53:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:53:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:53:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:53:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:53:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:53:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:53:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:53:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:53:18Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:53:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T11:53:22Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:53:24.361626 1 request.go:752] "Waited before sending request" delay="1.896947034s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/namespace-lister/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDExNjYsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:53:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T11:53:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:53:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:53:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:53:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:53:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T11:53:24Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:53:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T11:53:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:53:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:53:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:53:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:53:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:53:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:53:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:53:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T11:53:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:53:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T11:53:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T11:53:28Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,build.appstudio.redhat.com/build_type=docker,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=build-container,tekton.dev/task=buildah-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-build-container,tekton.dev/taskRunUID=928d1716-52f1-4086-acde-b0922fdcdc8e"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-use-trusted-artifact\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-build\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-push\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-sbom-syft-generate\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-prepare-sboms\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-upload-sbom\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=clone-repository,tekton.dev/task=git-clone-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-clone-repository,tekton.dev/taskRunUID=1c0f8bc5-dfdb-4e1d-a0ab-87a817e79d26"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-clone\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-symlink-check\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-create-trusted-artifact\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-clone\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-symlink-check\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-clone\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clone-repository-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-symlink-check\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=init,tekton.dev/task=init,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-init,tekton.dev/taskRunUID=1bd32f43-9e28-4f54-bee7-ea3a658fce0d"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-init-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-init-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-init-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-init-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-init-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-init-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-init-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-init\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-init-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-init-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=prefetch-dependencies,tekton.dev/task=prefetch-dependencies-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies,tekton.dev/taskRunUID=86fa5261-1324-4c31-90a0-26e8ba9e9d71"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-skip-ta\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-use-trusted-artifact\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-prefetch-dependencies\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-create-trusted-artifact\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-skip-ta\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-use-trusted-artifact\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-skip-ta\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-use-trusted-artifact\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T11:53:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"info","ts":"2026-05-07T11:53:32Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:53:34.361791 1 request.go:752] "Waited before sending request" delay="1.896945425s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/integration-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDEyOTEsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:53:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T11:53:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:53:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T11:53:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:53:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:53:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:53:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:53:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:53:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:53:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T11:53:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:53:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:54:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:54:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:54:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:54:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T11:54:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:54:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T11:54:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:54:38.358551 1 request.go:752] "Waited before sending request" delay="1.392044918s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/cert-manager-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDIwMzgsInN0YXJ0IjoicGlwZWxpbmVzLXNjYy1yb2xlYmluZGluZ1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:54:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:54:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:54:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:54:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:54:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:54:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:54:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:54:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:54:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T11:54:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T11:54:42Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:54:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T11:54:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:54:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:54:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:54:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:54:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:54:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:54:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T11:54:46Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:54:50.359203 1 request.go:752] "Waited before sending request" delay="1.994575264s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/enterprise-contract-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDIxNTEsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:54:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T11:54:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T11:54:50Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:54:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T11:54:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T11:54:54Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:54:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T11:54:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T11:54:56Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:54:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T11:54:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T11:54:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T11:54:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T11:54:58Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:55:00.360018 1 request.go:752] "Waited before sending request" delay="1.896459695s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/rhbk-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDIyODksInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:55:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:55:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:55:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:55:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:55:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:55:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:55:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:55:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:55:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:55:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:55:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:55:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:55:02Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:55:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T11:55:06Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:55:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T11:55:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:55:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:55:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:55:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:55:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T11:55:08Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:55:12.359065 1 request.go:752] "Waited before sending request" delay="1.99449547s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-ui/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDIzOTgsInN0YXJ0Ijoic3lzdGVtOmltYWdlLWJ1aWxkZXJzXHUwMDAwIn0&limit=5" {"level":"debug","ts":"2026-05-07T11:55:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T11:55:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:55:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T11:55:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:55:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T11:55:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:55:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:55:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:55:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:55:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:55:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:55:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T11:55:12Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=prefetch-dependencies,tekton.dev/task=prefetch-dependencies-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies,tekton.dev/taskRunUID=86fa5261-1324-4c31-90a0-26e8ba9e9d71"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,build.appstudio.redhat.com/build_type=docker,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=build-container,tekton.dev/task=buildah-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-build-container,tekton.dev/taskRunUID=928d1716-52f1-4086-acde-b0922fdcdc8e"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-use-trusted-artifact\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-build\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-push\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-sbom-syft-generate\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-prepare-sboms\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-upload-sbom\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=clone-repository,tekton.dev/task=git-clone-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-clone-repository,tekton.dev/taskRunUID=1c0f8bc5-dfdb-4e1d-a0ab-87a817e79d26"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=init,tekton.dev/task=init,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-init,tekton.dev/taskRunUID=1bd32f43-9e28-4f54-bee7-ea3a658fce0d"} {"level":"debug","ts":"2026-05-07T11:55:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"info","ts":"2026-05-07T11:55:16Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:55:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T11:55:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:55:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T11:55:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:55:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:55:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:55:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:55:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:55:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:55:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T11:55:20Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:55:24.360060 1 request.go:752] "Waited before sending request" delay="1.996060624s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/managed-tenant-oafxv/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDI1MzgsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"info","ts":"2026-05-07T11:55:24Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:55:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:55:28Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:55:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T11:55:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T11:55:32Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:55:36.359637 1 request.go:752] "Waited before sending request" delay="1.995045792s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-tpa/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDI3MTksInN0YXJ0Ijoicmh0cGEtb3BlcmF0b3ItYmluZC1qb2JcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T11:55:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:55:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:55:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:55:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:55:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:55:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:56:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:56:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T11:56:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T11:56:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:56:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:56:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T11:56:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:56:38.347004 1 request.go:752] "Waited before sending request" delay="1.377955674s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/build-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDM3MTQsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMFx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:56:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T11:56:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:56:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:56:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:56:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:56:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:56:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:56:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T11:56:40Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:56:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T11:56:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T11:56:44Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:56:48.347345 1 request.go:752] "Waited before sending request" delay="1.992438034s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-cli/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDM3OTksInN0YXJ0Ijoic3lzdGVtOmltYWdlLWJ1aWxkZXJzXHUwMDAwIn0&limit=5" {"level":"debug","ts":"2026-05-07T11:56:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T11:56:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T11:56:48Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:56:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T11:56:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T11:56:50Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:56:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T11:56:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T11:56:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T11:56:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T11:56:52Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:56:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:56:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:56:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:56:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:56:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:56:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:56:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:56:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:56:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:56:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:56:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:56:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:56:56Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:57:00.347040 1 request.go:752] "Waited before sending request" delay="1.99523427s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf-keycloak/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDM5NDksInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:57:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T11:57:00Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:57:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:57:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:57:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T11:57:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:57:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:57:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T11:57:02Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:57:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T11:57:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:57:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T11:57:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:57:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:57:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:57:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:57:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:57:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:57:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:57:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T11:57:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T11:57:06Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:57:10.347932 1 request.go:752] "Waited before sending request" delay="1.99319729s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/default-tenant/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDQxMTcsInN0YXJ0IjoicGlwZWxpbmVzLXNjYy1yb2xlYmluZGluZ1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,build.appstudio.redhat.com/build_type=docker,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=build-image-index,tekton.dev/task=build-image-index-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-build-image-index,tekton.dev/taskRunUID=7e90f568-f3f3-4490-8adf-e23c7d2efe51"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-build\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-create-sbom\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-upload-sbom\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-image-index-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=clamav-scan,tekton.dev/task=clamav-scan-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-clamav-scan,tekton.dev/taskRunUID=6e217671-97ee-49a7-b4a5-20db596ee2a8"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-extract-and-scan-image\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-upload\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=deprecated-base-image-check,tekton.dev/task=deprecated-image-check,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check,tekton.dev/taskRunUID=25290786-aa32-4203-8224-1c9ea10427b8"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-check-images\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=prefetch-dependencies,tekton.dev/task=prefetch-dependencies-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies,tekton.dev/taskRunUID=86fa5261-1324-4c31-90a0-26e8ba9e9d71"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=rpms-signature-scan,tekton.dev/task=rpms-signature-scan,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan,tekton.dev/taskRunUID=0418ba0d-bdbf-46af-89ba-76ff6cd964a4"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-rpms-signature-scan\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-output-results\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=sast-shell-check,tekton.dev/task=sast-shell-check-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check,tekton.dev/taskRunUID=aa2230fa-34b9-4f08-b680-410c1ccdaa32"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-use-trusted-artifact\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-sast-shell-check\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-upload\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-use-trusted-artifact\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-use-trusted-artifact\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=clone-repository,tekton.dev/task=git-clone-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-clone-repository,tekton.dev/taskRunUID=1c0f8bc5-dfdb-4e1d-a0ab-87a817e79d26"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=init,tekton.dev/task=init,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-init,tekton.dev/taskRunUID=1bd32f43-9e28-4f54-bee7-ea3a658fce0d"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=sast-unicode-check,tekton.dev/task=sast-unicode-check-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check,tekton.dev/taskRunUID=a4452541-12ac-48da-81e4-8750b861b55f"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-use-trusted-artifact\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-sast-unicode-check\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-upload\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-use-trusted-artifact\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-use-trusted-artifact\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=tpa-scan,tekton.dev/task=tpa-scan,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-tpa-scan,tekton.dev/taskRunUID=eb3e9019-9599-4aa3-97d2-7d2ffc08261d"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-get-vulnerabilities\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-oci-attach-report\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-conftest-vulnerabilities\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,build.appstudio.redhat.com/build_type=docker,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=build-container,tekton.dev/task=buildah-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-build-container,tekton.dev/taskRunUID=928d1716-52f1-4086-acde-b0922fdcdc8e"} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:57:10Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-build-container-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"info","ts":"2026-05-07T11:57:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:57:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T11:57:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:57:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:57:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:57:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:57:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:57:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:57:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:57:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T11:57:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T11:57:14Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:57:18Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:57:20.348286 1 request.go:752] "Waited before sending request" delay="1.911631889s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDQyOTksInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:57:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:57:22Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:57:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T11:57:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T11:57:26Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:57:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:57:30Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:57:32.348058 1 request.go:752] "Waited before sending request" delay="1.912921764s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDQ0NTEsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:57:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:57:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:57:32Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:57:34Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:57:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:57:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:57:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:57:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:57:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:57:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T11:58:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T11:58:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T11:58:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T11:58:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T11:58:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T11:58:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T11:58:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T11:58:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:58:38.332846 1 request.go:752] "Waited before sending request" delay="1.34508767s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/default-tenant/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDU1MzIsInN0YXJ0IjoicGlwZWxpbmVzLXNjYy1yb2xlYmluZGluZ1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=rpms-signature-scan,tekton.dev/task=rpms-signature-scan,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan,tekton.dev/taskRunUID=0418ba0d-bdbf-46af-89ba-76ff6cd964a4"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-rpms-signature-scan\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-output-results\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=tpa-scan,tekton.dev/task=tpa-scan,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-tpa-scan,tekton.dev/taskRunUID=eb3e9019-9599-4aa3-97d2-7d2ffc08261d"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-get-vulnerabilities\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-oci-attach-report\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-conftest-vulnerabilities\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-tpa-scan-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=0.1,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,build.appstudio.redhat.com/pipeline=enterprise-contract,pac.test.appstudio.openshift.io/cancel-in-progress=false,pac.test.appstudio.openshift.io/check-run-id=74809009768,pac.test.appstudio.openshift.io/event-type=push,pac.test.appstudio.openshift.io/original-prname=tsf-comp-6vc6m-on-push,pac.test.appstudio.openshift.io/repository=tsf-comp-6vc6m,pac.test.appstudio.openshift.io/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pac.test.appstudio.openshift.io/state=completed,pac.test.appstudio.openshift.io/url-org=rhads-tsf-qe,pac.test.appstudio.openshift.io/url-repository=testrepo,pipelines.appstudio.openshift.io/type=test,tekton.dev/memberOf=tasks,tekton.dev/pipeline=enterprise-contract,tekton.dev/pipelineRun=my-integration-test-dyhk-tqjq7,tekton.dev/pipelineRunUID=24b2cb3f-69d6-4786-a3a9-0c64cf2a9f8b,tekton.dev/pipelineTask=verify,tekton.dev/task=verify-enterprise-contract,tekton.dev/taskRun=my-integration-test-dyhk-tqjq7-verify,tekton.dev/taskRunUID=1f15bf1d-4f31-4d95-8506-cc638a0df12f,test.appstudio.openshift.io/optional=false,test.appstudio.openshift.io/pipelinerunfinishtime=1778155068,test.appstudio.openshift.io/scenario=my-integration-test-dyhk,test.appstudio.openshift.io/type=component"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-verify-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-verify-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-verify-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"konflux-integration-runner\" not found"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-verify-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-verify-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-verify-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-verify-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-verify-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-detailed-report\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-verify-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-verify-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-verify-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-detailed-report\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,build.appstudio.redhat.com/build_type=docker,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=build-container,tekton.dev/task=buildah-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-build-container,tekton.dev/taskRunUID=928d1716-52f1-4086-acde-b0922fdcdc8e"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,build.appstudio.redhat.com/build_type=docker,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=build-image-index,tekton.dev/task=build-image-index-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-build-image-index,tekton.dev/taskRunUID=7e90f568-f3f3-4490-8adf-e23c7d2efe51"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=clone-repository,tekton.dev/task=git-clone-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-clone-repository,tekton.dev/taskRunUID=1c0f8bc5-dfdb-4e1d-a0ab-87a817e79d26"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=init,tekton.dev/task=init,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-init,tekton.dev/taskRunUID=1bd32f43-9e28-4f54-bee7-ea3a658fce0d"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=prefetch-dependencies,tekton.dev/task=prefetch-dependencies-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies,tekton.dev/taskRunUID=86fa5261-1324-4c31-90a0-26e8ba9e9d71"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=sast-shell-check,tekton.dev/task=sast-shell-check-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check,tekton.dev/taskRunUID=aa2230fa-34b9-4f08-b680-410c1ccdaa32"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-use-trusted-artifact\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-sast-shell-check\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-upload\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-use-trusted-artifact\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-use-trusted-artifact\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=sast-unicode-check,tekton.dev/task=sast-unicode-check-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check,tekton.dev/taskRunUID=a4452541-12ac-48da-81e4-8750b861b55f"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-use-trusted-artifact\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-sast-unicode-check\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-upload\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-use-trusted-artifact\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-use-trusted-artifact\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=0.1,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,build.appstudio.redhat.com/pipeline=enterprise-contract,pac.test.appstudio.openshift.io/cancel-in-progress=false,pac.test.appstudio.openshift.io/check-run-id=74809009768,pac.test.appstudio.openshift.io/event-type=push,pac.test.appstudio.openshift.io/original-prname=tsf-comp-6vc6m-on-push,pac.test.appstudio.openshift.io/repository=tsf-comp-6vc6m,pac.test.appstudio.openshift.io/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pac.test.appstudio.openshift.io/state=completed,pac.test.appstudio.openshift.io/url-org=rhads-tsf-qe,pac.test.appstudio.openshift.io/url-repository=testrepo,pipelines.appstudio.openshift.io/type=test,tekton.dev/memberOf=tasks,tekton.dev/pipeline=enterprise-contract,tekton.dev/pipelineRun=my-integration-test-dyhk-tqjq7,tekton.dev/pipelineRunUID=24b2cb3f-69d6-4786-a3a9-0c64cf2a9f8b,tekton.dev/pipelineTask=collect-keyless-params,tekton.dev/task=collect-keyless-params,tekton.dev/taskRun=my-integration-test-dyhk-tqjq7-collect-keyless-params,tekton.dev/taskRunUID=a65bff7b-57fe-42db-8f64-956e472e0056,test.appstudio.openshift.io/optional=false,test.appstudio.openshift.io/pipelinerunfinishtime=1778155068,test.appstudio.openshift.io/scenario=my-integration-test-dyhk,test.appstudio.openshift.io/type=component"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-collect-keyless-params-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-collect-keyless-params-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-collect-keyless-params-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"konflux-integration-runner\" not found"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-collect-keyless-params-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-collect-keyless-params-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-collect-keyless-params-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-collect-keyless-params-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-collect-keyless-params-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"my-integration-test-dyhk-tqjq7-collect-keyless-params-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=clamav-scan,tekton.dev/task=clamav-scan-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-clamav-scan,tekton.dev/taskRunUID=6e217671-97ee-49a7-b4a5-20db596ee2a8"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-extract-and-scan-image\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-upload\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-clamav-scan-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=deprecated-base-image-check,tekton.dev/task=deprecated-image-check,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check,tekton.dev/taskRunUID=25290786-aa32-4203-8224-1c9ea10427b8"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"build-pipeline-tsf-comp-6vc6m\" not found"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"prepare\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"place-scripts\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:38Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"default-tenant","object":"tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check-pod","kind":"Pod","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"step-check-images\" is not set to runAsNonRoot"} {"level":"info","ts":"2026-05-07T11:58:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:58:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T11:58:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:58:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:58:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:58:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:58:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:58:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T11:58:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T11:58:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T11:58:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T11:58:42Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":2,"labels":"app.kubernetes.io/component=affinity-assistant,app.kubernetes.io/instance=affinity-assistant-22747d4f9b,apps.kubernetes.io/pod-index=0,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,controller-revision-hash=affinity-assistant-22747d4f9b-5769776b7d,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,statefulset.kubernetes.io/pod-name=affinity-assistant-22747d4f9b-0,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"affinity-assistant\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=verify-access-to-resources,tekton.dev/task=verify-access-to-resources,tekton.dev/taskRun=managed-956lk-verify-access-to-resources,tekton.dev/taskRunUID=7c2242ea-4562-4fcb-9a41-6aa5964a5ccb"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":2,"labels":"app.kubernetes.io/component=affinity-assistant,app.kubernetes.io/instance=affinity-assistant-22747d4f9b,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk"} {"level":"debug","ts":"2026-05-07T11:58:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"managed-tenant-oafxv"} {"level":"info","ts":"2026-05-07T11:58:46Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:58:50.332063 1 request.go:752] "Waited before sending request" delay="1.995248069s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDU3MzEsInN0YXJ0IjoicGlwZWxpbmVzLXNjYy1yb2xlYmluZGluZ1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T11:58:50Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T11:58:50Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:58:54Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T11:58:54Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T11:58:54Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:58:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T11:58:58Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:59:00.332777 1 request.go:752] "Waited before sending request" delay="1.901377722s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDU4NzcsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T11:59:00Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T11:59:00Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T11:59:00Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T11:59:02Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:59:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T11:59:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T11:59:04Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:59:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T11:59:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:59:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T11:59:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:59:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T11:59:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:59:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T11:59:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:59:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T11:59:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T11:59:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T11:59:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T11:59:08Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:59:10.333173 1 request.go:752] "Waited before sending request" delay="1.882853121s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/rhtpa-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDYxNDgsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"info","ts":"2026-05-07T11:59:12Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:59:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:59:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:59:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:59:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:59:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T11:59:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T11:59:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T11:59:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T11:59:16Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T11:59:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T11:59:20Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:59:22.332778 1 request.go:752] "Waited before sending request" delay="1.87676707s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/cert-manager-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDY1MzUsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbi1zZXJ2aWNlYWNjb3VudHMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T11:59:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T11:59:24Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:59:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:59:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:59:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:59:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:59:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T11:59:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T11:59:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T11:59:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T11:59:28Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 11:59:32.333385 1 request.go:752] "Waited before sending request" delay="1.996044465s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/build-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDY2OTAsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T11:59:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:59:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:59:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T11:59:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:59:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:59:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T11:59:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T11:59:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T11:59:32Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:59:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T11:59:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T11:59:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T11:59:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T11:59:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T11:59:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T12:00:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T12:00:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T12:00:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T12:00:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T12:00:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T12:00:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T12:00:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=0.1,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,build.appstudio.redhat.com/pipeline=enterprise-contract,pac.test.appstudio.openshift.io/cancel-in-progress=false,pac.test.appstudio.openshift.io/check-run-id=74809009768,pac.test.appstudio.openshift.io/event-type=push,pac.test.appstudio.openshift.io/original-prname=tsf-comp-6vc6m-on-push,pac.test.appstudio.openshift.io/repository=tsf-comp-6vc6m,pac.test.appstudio.openshift.io/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pac.test.appstudio.openshift.io/state=completed,pac.test.appstudio.openshift.io/url-org=rhads-tsf-qe,pac.test.appstudio.openshift.io/url-repository=testrepo,pipelines.appstudio.openshift.io/type=test,tekton.dev/memberOf=tasks,tekton.dev/pipeline=enterprise-contract,tekton.dev/pipelineRun=my-integration-test-dyhk-tqjq7,tekton.dev/pipelineRunUID=24b2cb3f-69d6-4786-a3a9-0c64cf2a9f8b,tekton.dev/pipelineTask=collect-keyless-params,tekton.dev/task=collect-keyless-params,tekton.dev/taskRun=my-integration-test-dyhk-tqjq7-collect-keyless-params,tekton.dev/taskRunUID=a65bff7b-57fe-42db-8f64-956e472e0056,test.appstudio.openshift.io/optional=false,test.appstudio.openshift.io/pipelinerunfinishtime=1778155068,test.appstudio.openshift.io/scenario=my-integration-test-dyhk,test.appstudio.openshift.io/type=component"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=0.1,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,build.appstudio.redhat.com/pipeline=enterprise-contract,pac.test.appstudio.openshift.io/cancel-in-progress=false,pac.test.appstudio.openshift.io/check-run-id=74809009768,pac.test.appstudio.openshift.io/event-type=push,pac.test.appstudio.openshift.io/original-prname=tsf-comp-6vc6m-on-push,pac.test.appstudio.openshift.io/repository=tsf-comp-6vc6m,pac.test.appstudio.openshift.io/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pac.test.appstudio.openshift.io/state=completed,pac.test.appstudio.openshift.io/url-org=rhads-tsf-qe,pac.test.appstudio.openshift.io/url-repository=testrepo,pipelines.appstudio.openshift.io/type=test,tekton.dev/memberOf=tasks,tekton.dev/pipeline=enterprise-contract,tekton.dev/pipelineRun=my-integration-test-dyhk-tqjq7,tekton.dev/pipelineRunUID=24b2cb3f-69d6-4786-a3a9-0c64cf2a9f8b,tekton.dev/pipelineTask=verify,tekton.dev/task=verify-enterprise-contract,tekton.dev/taskRun=my-integration-test-dyhk-tqjq7-verify,tekton.dev/taskRunUID=1f15bf1d-4f31-4d95-8506-cc638a0df12f,test.appstudio.openshift.io/optional=false,test.appstudio.openshift.io/pipelinerunfinishtime=1778155068,test.appstudio.openshift.io/scenario=my-integration-test-dyhk,test.appstudio.openshift.io/type=component"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,build.appstudio.redhat.com/build_type=docker,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=build-container,tekton.dev/task=buildah-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-build-container,tekton.dev/taskRunUID=928d1716-52f1-4086-acde-b0922fdcdc8e"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=init,tekton.dev/task=init,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-init,tekton.dev/taskRunUID=1bd32f43-9e28-4f54-bee7-ea3a658fce0d"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=prefetch-dependencies,tekton.dev/task=prefetch-dependencies-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies,tekton.dev/taskRunUID=86fa5261-1324-4c31-90a0-26e8ba9e9d71"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=rpms-signature-scan,tekton.dev/task=rpms-signature-scan,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan,tekton.dev/taskRunUID=0418ba0d-bdbf-46af-89ba-76ff6cd964a4"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=sast-shell-check,tekton.dev/task=sast-shell-check-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check,tekton.dev/taskRunUID=aa2230fa-34b9-4f08-b680-410c1ccdaa32"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=tpa-scan,tekton.dev/task=tpa-scan,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-tpa-scan,tekton.dev/taskRunUID=eb3e9019-9599-4aa3-97d2-7d2ffc08261d"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,build.appstudio.redhat.com/build_type=docker,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=build-image-index,tekton.dev/task=build-image-index-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-build-image-index,tekton.dev/taskRunUID=7e90f568-f3f3-4490-8adf-e23c7d2efe51"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=clamav-scan,tekton.dev/task=clamav-scan-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-clamav-scan,tekton.dev/taskRunUID=6e217671-97ee-49a7-b4a5-20db596ee2a8"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=clone-repository,tekton.dev/task=git-clone-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-clone-repository,tekton.dev/taskRunUID=1c0f8bc5-dfdb-4e1d-a0ab-87a817e79d26"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=deprecated-base-image-check,tekton.dev/task=deprecated-image-check,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check,tekton.dev/taskRunUID=25290786-aa32-4203-8224-1c9ea10427b8"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=sast-unicode-check,tekton.dev/task=sast-unicode-check-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check,tekton.dev/taskRunUID=a4452541-12ac-48da-81e4-8750b861b55f"} {"level":"debug","ts":"2026-05-07T12:00:37Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"info","ts":"2026-05-07T12:00:37Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:00:38.365868 1 request.go:752] "Waited before sending request" delay="1.22312654s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/integration-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDgwMTEsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":3,"labels":"batch.kubernetes.io/controller-uid=1e06b07d-ee22-4933-a8d2-c911a00ddffd,batch.kubernetes.io/job-name=integration-service-snapshot-garbage-collector-29635920,controller-uid=1e06b07d-ee22-4933-a8d2-c911a00ddffd,job-name=integration-service-snapshot-garbage-collector-29635920"} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-snapshot-garbage-collector","kind":"CronJob","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-snapshot-garbage-collector","kind":"CronJob","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-snapshot-garbage-collector","kind":"CronJob","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"integration-service","object":"integration-service-snapshot-garbage-collector","kind":"CronJob","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"info","ts":"2026-05-07T12:00:40Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=collect-data,tekton.dev/task=collect-data,tekton.dev/taskRun=managed-956lk-collect-data,tekton.dev/taskRunUID=9329ed6d-66ff-404b-a6fe-845256530704"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-data-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-data-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-data-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-data-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-data-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-data-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-data-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-data-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-data-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=collect-signing-params,tekton.dev/task=collect-signing-params,tekton.dev/taskRun=managed-956lk-collect-signing-params,tekton.dev/taskRunUID=be4583d0-3c8c-472e-9025-4d1c4acefd01"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-signing-params-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-signing-params-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-signing-params-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-signing-params-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-signing-params-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-signing-params-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-signing-params-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-signing-params-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-signing-params-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=collect-tpa-params,tekton.dev/task=collect-tpa-params,tekton.dev/taskRun=managed-956lk-collect-tpa-params,tekton.dev/taskRunUID=85a1a974-0b6a-4224-b882-4c3f8e4a502e"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-tpa-params-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-tpa-params-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-tpa-params-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-tpa-params-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-tpa-params-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-tpa-params-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-tpa-params-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-tpa-params-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-tpa-params-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=filter-already-released-images,tekton.dev/taskRun=managed-956lk-filter-already-released-images,tekton.dev/taskRunUID=ef5f61c6-46df-4ea9-8dc0-4230f027fc9c"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-filter-already-released-images-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-filter-already-released-images-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-filter-already-released-images-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-filter-already-released-images-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-filter-already-released-images-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-filter-already-released-images-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-filter-already-released-images-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-filter-already-released-images-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-filter-already-released-images-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=reduce-snapshot,tekton.dev/task=reduce-snapshot,tekton.dev/taskRun=managed-956lk-reduce-snapshot,tekton.dev/taskRunUID=358e292e-7697-40d5-8ed3-0abd544d4903"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-reduce-snapshot-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-reduce-snapshot-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-reduce-snapshot-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-reduce-snapshot-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-reduce-snapshot-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-reduce-snapshot-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-reduce-snapshot-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-reduce-snapshot-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-reduce-snapshot-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=verify-access-to-resources,tekton.dev/task=verify-access-to-resources,tekton.dev/taskRun=managed-956lk-verify-access-to-resources,tekton.dev/taskRunUID=7c2242ea-4562-4fcb-9a41-6aa5964a5ccb"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-verify-access-to-resources-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":2,"labels":"app.kubernetes.io/component=affinity-assistant,app.kubernetes.io/instance=affinity-assistant-22747d4f9b,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"affinity-assistant\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"affinity-assistant\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":2,"labels":"app.kubernetes.io/component=affinity-assistant,app.kubernetes.io/instance=affinity-assistant-22747d4f9b,apps.kubernetes.io/pod-index=0,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,controller-revision-hash=affinity-assistant-22747d4f9b-5769776b7d,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,statefulset.kubernetes.io/pod-name=affinity-assistant-22747d4f9b-0,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"affinity-assistant-22747d4f9b","kind":"StatefulSet","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"affinity-assistant\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=apply-mapping,tekton.dev/task=apply-mapping,tekton.dev/taskRun=managed-956lk-apply-mapping,tekton.dev/taskRunUID=597cb733-ebb7-4821-b7c0-a84633bd464f"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-apply-mapping-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-apply-mapping-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-apply-mapping-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-apply-mapping-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-apply-mapping-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-apply-mapping-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-apply-mapping-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-apply-mapping-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-apply-mapping-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=check-data-keys,tekton.dev/task=check-data-keys,tekton.dev/taskRun=managed-956lk-check-data-keys,tekton.dev/taskRunUID=cbb3e717-60c9-41b1-8d21-57c009c1a2df"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-check-data-keys-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-check-data-keys-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-check-data-keys-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-check-data-keys-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-check-data-keys-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-check-data-keys-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-check-data-keys-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-check-data-keys-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-check-data-keys-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=collect-registry-token-secret,tekton.dev/task=collect-registry-token-secret,tekton.dev/taskRun=managed-956lk-collect-registry-token-secret,tekton.dev/taskRunUID=73644d57-4c20-4c85-82f8-d17262e0fd5c"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-registry-token-secret-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-registry-token-secret-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-registry-token-secret-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-registry-token-secret-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-registry-token-secret-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-registry-token-secret-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-registry-token-secret-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-registry-token-secret-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-registry-token-secret-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=collect-task-params,tekton.dev/task=collect-task-params,tekton.dev/taskRun=managed-956lk-collect-task-params,tekton.dev/taskRunUID=2aaf860b-14ec-47ff-ac0e-f42919b06cb8"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-task-params-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-task-params-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-task-params-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-collect-task-params-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=push-snapshot,tekton.dev/task=push-snapshot,tekton.dev/taskRun=managed-956lk-push-snapshot,tekton.dev/taskRunUID=a736d372-954e-4cd4-b7b9-00689ac6a0be"} {"level":"debug","ts":"2026-05-07T12:00:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=0.1,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=verify-conforma,tekton.dev/task=verify-conforma-konflux-ta,tekton.dev/taskRun=managed-956lk-verify-conforma,tekton.dev/taskRunUID=b1945a24-354a-4af5-9d8c-a5a09d5ec8ee"} {"level":"info","ts":"2026-05-07T12:00:44Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:00:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T12:00:48Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:00:50.366771 1 request.go:752] "Waited before sending request" delay="1.895864243s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-info/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDgxODEsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T12:00:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T12:00:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T12:00:52Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:00:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T12:00:56Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:00:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T12:00:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T12:00:58Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T12:01:00Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:01:02.367226 1 request.go:752] "Waited before sending request" delay="1.866913355s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/trusted-artifact-signer/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDg0MTcsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T12:01:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T12:01:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T12:01:02Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:01:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T12:01:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:01:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T12:01:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:01:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T12:01:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:01:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T12:01:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:01:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T12:01:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:01:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T12:01:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T12:01:06Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T12:01:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:01:14.367118 1 request.go:752] "Waited before sending request" delay="1.995046617s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/release-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDg2MzIsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T12:01:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T12:01:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T12:01:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T12:01:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T12:01:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T12:01:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T12:01:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T12:01:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T12:01:14Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T12:01:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T12:01:18Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:01:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T12:01:22Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:01:26.367045 1 request.go:752] "Waited before sending request" delay="1.99587561s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/image-controller/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDg3NzMsInN0YXJ0Ijoic3lzdGVtOmltYWdlLWJ1aWxkZXJzXHUwMDAwIn0&limit=5" {"level":"debug","ts":"2026-05-07T12:01:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T12:01:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T12:01:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T12:01:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T12:01:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T12:01:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T12:01:26Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T12:01:26Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T12:01:26Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:01:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T12:01:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T12:01:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T12:01:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T12:01:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T12:01:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T12:01:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T12:01:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T12:01:30Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:01:34Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T12:01:34Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T12:01:34Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:01:38.365873 1 request.go:752] "Waited before sending request" delay="1.994679974s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-cli/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDg5MTMsInN0YXJ0Ijoic3lzdGVtOmltYWdlLWJ1aWxkZXJzXHUwMDAwIn0&limit=5" {"level":"debug","ts":"2026-05-07T12:01:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T12:01:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T12:01:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:01:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":3,"labels":"batch.kubernetes.io/controller-uid=082ba1e8-7a00-4975-bb43-436004f58eb9,batch.kubernetes.io/job-name=segment-bridge-29635920,controller-uid=082ba1e8-7a00-4975-bb43-436004f58eb9,job-name=segment-bridge-29635920"} {"level":"debug","ts":"2026-05-07T12:01:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T12:01:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"segment-bridge","object":"segment-bridge","kind":"CronJob","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:01:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"segment-bridge","object":"segment-bridge","kind":"CronJob","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:01:40Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"segment-bridge","object":"segment-bridge","kind":"CronJob","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"info","ts":"2026-05-07T12:01:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T12:02:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T12:02:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T12:02:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,build.appstudio.redhat.com/build_type=docker,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=build-image-index,tekton.dev/task=build-image-index-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-build-image-index,tekton.dev/taskRunUID=7e90f568-f3f3-4490-8adf-e23c7d2efe51"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=clamav-scan,tekton.dev/task=clamav-scan-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-clamav-scan,tekton.dev/taskRunUID=6e217671-97ee-49a7-b4a5-20db596ee2a8"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=clone-repository,tekton.dev/task=git-clone-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-clone-repository,tekton.dev/taskRunUID=1c0f8bc5-dfdb-4e1d-a0ab-87a817e79d26"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=deprecated-base-image-check,tekton.dev/task=deprecated-image-check,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check,tekton.dev/taskRunUID=25290786-aa32-4203-8224-1c9ea10427b8"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=sast-shell-check,tekton.dev/task=sast-shell-check-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check,tekton.dev/taskRunUID=aa2230fa-34b9-4f08-b680-410c1ccdaa32"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=sast-unicode-check,tekton.dev/task=sast-unicode-check-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check,tekton.dev/taskRunUID=a4452541-12ac-48da-81e4-8750b861b55f"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=tpa-scan,tekton.dev/task=tpa-scan,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-tpa-scan,tekton.dev/taskRunUID=eb3e9019-9599-4aa3-97d2-7d2ffc08261d"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=0.1,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,build.appstudio.redhat.com/pipeline=enterprise-contract,pac.test.appstudio.openshift.io/cancel-in-progress=false,pac.test.appstudio.openshift.io/check-run-id=74809009768,pac.test.appstudio.openshift.io/event-type=push,pac.test.appstudio.openshift.io/original-prname=tsf-comp-6vc6m-on-push,pac.test.appstudio.openshift.io/repository=tsf-comp-6vc6m,pac.test.appstudio.openshift.io/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pac.test.appstudio.openshift.io/state=completed,pac.test.appstudio.openshift.io/url-org=rhads-tsf-qe,pac.test.appstudio.openshift.io/url-repository=testrepo,pipelines.appstudio.openshift.io/type=test,tekton.dev/memberOf=tasks,tekton.dev/pipeline=enterprise-contract,tekton.dev/pipelineRun=my-integration-test-dyhk-tqjq7,tekton.dev/pipelineRunUID=24b2cb3f-69d6-4786-a3a9-0c64cf2a9f8b,tekton.dev/pipelineTask=collect-keyless-params,tekton.dev/task=collect-keyless-params,tekton.dev/taskRun=my-integration-test-dyhk-tqjq7-collect-keyless-params,tekton.dev/taskRunUID=a65bff7b-57fe-42db-8f64-956e472e0056,test.appstudio.openshift.io/optional=false,test.appstudio.openshift.io/pipelinerunfinishtime=1778155068,test.appstudio.openshift.io/scenario=my-integration-test-dyhk,test.appstudio.openshift.io/type=component"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=0.1,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,build.appstudio.redhat.com/pipeline=enterprise-contract,pac.test.appstudio.openshift.io/cancel-in-progress=false,pac.test.appstudio.openshift.io/check-run-id=74809009768,pac.test.appstudio.openshift.io/event-type=push,pac.test.appstudio.openshift.io/original-prname=tsf-comp-6vc6m-on-push,pac.test.appstudio.openshift.io/repository=tsf-comp-6vc6m,pac.test.appstudio.openshift.io/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pac.test.appstudio.openshift.io/state=completed,pac.test.appstudio.openshift.io/url-org=rhads-tsf-qe,pac.test.appstudio.openshift.io/url-repository=testrepo,pipelines.appstudio.openshift.io/type=test,tekton.dev/memberOf=tasks,tekton.dev/pipeline=enterprise-contract,tekton.dev/pipelineRun=my-integration-test-dyhk-tqjq7,tekton.dev/pipelineRunUID=24b2cb3f-69d6-4786-a3a9-0c64cf2a9f8b,tekton.dev/pipelineTask=verify,tekton.dev/task=verify-enterprise-contract,tekton.dev/taskRun=my-integration-test-dyhk-tqjq7-verify,tekton.dev/taskRunUID=1f15bf1d-4f31-4d95-8506-cc638a0df12f,test.appstudio.openshift.io/optional=false,test.appstudio.openshift.io/pipelinerunfinishtime=1778155068,test.appstudio.openshift.io/scenario=my-integration-test-dyhk,test.appstudio.openshift.io/type=component"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,build.appstudio.redhat.com/build_type=docker,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=build-container,tekton.dev/task=buildah-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-build-container,tekton.dev/taskRunUID=928d1716-52f1-4086-acde-b0922fdcdc8e"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=init,tekton.dev/task=init,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-init,tekton.dev/taskRunUID=1bd32f43-9e28-4f54-bee7-ea3a658fce0d"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=prefetch-dependencies,tekton.dev/task=prefetch-dependencies-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies,tekton.dev/taskRunUID=86fa5261-1324-4c31-90a0-26e8ba9e9d71"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=rpms-signature-scan,tekton.dev/task=rpms-signature-scan,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan,tekton.dev/taskRunUID=0418ba0d-bdbf-46af-89ba-76ff6cd964a4"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"info","ts":"2026-05-07T12:02:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":3,"labels":"batch.kubernetes.io/controller-uid=1e06b07d-ee22-4933-a8d2-c911a00ddffd,batch.kubernetes.io/job-name=integration-service-snapshot-garbage-collector-29635920,controller-uid=1e06b07d-ee22-4933-a8d2-c911a00ddffd,job-name=integration-service-snapshot-garbage-collector-29635920"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T12:02:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=collect-registry-token-secret,tekton.dev/task=collect-registry-token-secret,tekton.dev/taskRun=managed-956lk-collect-registry-token-secret,tekton.dev/taskRunUID=73644d57-4c20-4c85-82f8-d17262e0fd5c"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"managed-tenant-oafxv"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=process-component-sbom,tekton.dev/taskRun=managed-956lk-process-component-sbom,tekton.dev/taskRunUID=928335ef-64f8-46d3-b93f-d2a157e46c79"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-use-trusted-artifact\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-create-trusted-artifact\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-use-trusted-artifact\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-process-component-sbom-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"step-create-trusted-artifact\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=verify-access-to-resources,tekton.dev/task=verify-access-to-resources,tekton.dev/taskRun=managed-956lk-verify-access-to-resources,tekton.dev/taskRunUID=7c2242ea-4562-4fcb-9a41-6aa5964a5ccb"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"managed-tenant-oafxv"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=0.1,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=verify-conforma,tekton.dev/task=verify-conforma-konflux-ta,tekton.dev/taskRun=managed-956lk-verify-conforma,tekton.dev/taskRunUID=b1945a24-354a-4af5-9d8c-a5a09d5ec8ee"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"managed-tenant-oafxv"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=apply-mapping,tekton.dev/task=apply-mapping,tekton.dev/taskRun=managed-956lk-apply-mapping,tekton.dev/taskRunUID=597cb733-ebb7-4821-b7c0-a84633bd464f"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"managed-tenant-oafxv"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=collect-signing-params,tekton.dev/task=collect-signing-params,tekton.dev/taskRun=managed-956lk-collect-signing-params,tekton.dev/taskRunUID=be4583d0-3c8c-472e-9025-4d1c4acefd01"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"managed-tenant-oafxv"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=collect-task-params,tekton.dev/task=collect-task-params,tekton.dev/taskRun=managed-956lk-collect-task-params,tekton.dev/taskRunUID=2aaf860b-14ec-47ff-ac0e-f42919b06cb8"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"managed-tenant-oafxv"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=push-snapshot,tekton.dev/task=push-snapshot,tekton.dev/taskRun=managed-956lk-push-snapshot,tekton.dev/taskRunUID=a736d372-954e-4cd4-b7b9-00689ac6a0be"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-push-snapshot-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-push-snapshot-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-push-snapshot-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-push-snapshot-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-push-snapshot-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-push-snapshot-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-push-snapshot-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-push-snapshot-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-push-snapshot-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=update-cr-status,tekton.dev/taskRun=managed-956lk-update-cr-status,tekton.dev/taskRunUID=80463a38-bf98-4552-92f3-c83e93905f46"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-update-cr-status-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-update-cr-status-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-update-cr-status-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-update-cr-status-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-update-cr-status-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-update-cr-status-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-update-cr-status-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-update-cr-status-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-update-cr-status-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=check-data-keys,tekton.dev/task=check-data-keys,tekton.dev/taskRun=managed-956lk-check-data-keys,tekton.dev/taskRunUID=cbb3e717-60c9-41b1-8d21-57c009c1a2df"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"managed-tenant-oafxv"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=collect-data,tekton.dev/task=collect-data,tekton.dev/taskRun=managed-956lk-collect-data,tekton.dev/taskRunUID=9329ed6d-66ff-404b-a6fe-845256530704"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"managed-tenant-oafxv"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=collect-tpa-params,tekton.dev/task=collect-tpa-params,tekton.dev/taskRun=managed-956lk-collect-tpa-params,tekton.dev/taskRunUID=85a1a974-0b6a-4224-b882-4c3f8e4a502e"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"managed-tenant-oafxv"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=sign-image-cosign-keyless,tekton.dev/task=sign-image-cosign-keyless,tekton.dev/taskRun=managed-956lk-sign-image-cosign-keyless,tekton.dev/taskRunUID=5cf21121-46d9-44c6-ac29-fc9943908870"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-sign-image-cosign-keyless-pod","kind":"Pod","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-sign-image-cosign-keyless-pod","kind":"Pod","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-sign-image-cosign-keyless-pod","kind":"Pod","validation":"non-existent-service-account","check_description":"Indicates when pods reference a service account that is not found.","check_remediation":"Create the missing service account, or refer to an existing service account.","check_failure_reason":"serviceAccount \"release-pipeline\" not found"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-sign-image-cosign-keyless-pod","kind":"Pod","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-sign-image-cosign-keyless-pod","kind":"Pod","validation":"restart-policy","check_description":"Indicates when a deployment-like object does not use a restart policy","check_remediation":"Set up the restart policy for your object to 'Always' or 'OnFailure' to increase the fault tolerance.","check_failure_reason":"object has a restart policy defined with 'Never' but the only accepted restart policies are '[Always OnFailure]'"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-sign-image-cosign-keyless-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-sign-image-cosign-keyless-pod","kind":"Pod","validation":"unset-cpu-requirements","check_description":"Indicates when containers do not have CPU requests and limits set.","check_remediation":"Set CPU requests for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has cpu request 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-sign-image-cosign-keyless-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"prepare\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"managed-tenant-oafxv","object":"managed-956lk-sign-image-cosign-keyless-pod","kind":"Pod","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"place-scripts\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=filter-already-released-images,tekton.dev/taskRun=managed-956lk-filter-already-released-images,tekton.dev/taskRunUID=ef5f61c6-46df-4ea9-8dc0-4230f027fc9c"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"managed-tenant-oafxv"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"managed-tenant-oafxv","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/service=release,appstudio.openshift.io/snapshot=tsf-app-20260507-115054-000,pipelines.appstudio.openshift.io/type=managed,release.appstudio.openshift.io/name=tsf-app-20260507-115054-000-0b6ee4b-qtsvt,release.appstudio.openshift.io/namespace=default-tenant,tekton.dev/memberOf=tasks,tekton.dev/pipeline=push-to-external-registry,tekton.dev/pipelineRun=managed-956lk,tekton.dev/pipelineRunUID=16e7395a-ae3f-4046-9cb2-3cfa9ae1aff1,tekton.dev/pipelineTask=reduce-snapshot,tekton.dev/task=reduce-snapshot,tekton.dev/taskRun=managed-956lk-reduce-snapshot,tekton.dev/taskRunUID=358e292e-7697-40d5-8ed3-0abd544d4903"} {"level":"debug","ts":"2026-05-07T12:02:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"managed-tenant-oafxv"} {"level":"info","ts":"2026-05-07T12:02:37Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:02:38.348570 1 request.go:752] "Waited before sending request" delay="1.294705713s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NDk4NzEsInN0YXJ0IjoicGlwZWxpbmVzLXNjYy1yb2xlYmluZGluZ1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:02:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T12:02:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:02:42Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T12:02:42Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T12:02:42Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:02:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T12:02:46Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:02:48.349071 1 request.go:752] "Waited before sending request" delay="1.892193148s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NTA1NzQsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T12:02:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T12:02:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T12:02:48Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T12:02:50Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:02:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T12:02:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:02:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:02:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T12:02:52Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:02:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T12:02:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:02:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T12:02:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:02:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T12:02:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:02:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T12:02:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:02:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T12:02:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:02:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T12:02:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T12:02:56Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:02:58.349393 1 request.go:752] "Waited before sending request" delay="1.892974664s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/rhtpa-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NTA3MDMsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"info","ts":"2026-05-07T12:03:00Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:03:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T12:03:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T12:03:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T12:03:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T12:03:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T12:03:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T12:03:04Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T12:03:04Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T12:03:04Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:03:08Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T12:03:08Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:03:10.349014 1 request.go:752] "Waited before sending request" delay="1.89252392s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/cert-manager-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NTA4NTQsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbi1zZXJ2aWNlYWNjb3VudHMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T12:03:12Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T12:03:12Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:03:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T12:03:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T12:03:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T12:03:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T12:03:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T12:03:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T12:03:16Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T12:03:16Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T12:03:16Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:03:20.349922 1 request.go:752] "Waited before sending request" delay="1.994086414s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/build-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NTA5NDIsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T12:03:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T12:03:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T12:03:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T12:03:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T12:03:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T12:03:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T12:03:20Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T12:03:20Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T12:03:20Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:03:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T12:03:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T12:03:24Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:03:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T12:03:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T12:03:28Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:03:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":3,"labels":"batch.kubernetes.io/controller-uid=082ba1e8-7a00-4975-bb43-436004f58eb9,batch.kubernetes.io/job-name=segment-bridge-29635920,controller-uid=082ba1e8-7a00-4975-bb43-436004f58eb9,job-name=segment-bridge-29635920"} {"level":"debug","ts":"2026-05-07T12:03:30Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T12:03:30Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T12:03:30Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:03:32.349448 1 request.go:752] "Waited before sending request" delay="1.879929102s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/tsf/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NTExMDcsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T12:03:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T12:03:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T12:03:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T12:03:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T12:03:32Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:03:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T12:03:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:03:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T12:03:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:03:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T12:03:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:03:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T12:03:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:03:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:03:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:03:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T12:03:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T12:03:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T12:03:40Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T12:04:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T12:04:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-installation,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":3,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6c97cd678f"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":7,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=5cc55b6ddd"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,batch.kubernetes.io/job-name=ctlog-createtree-job-pgsqt,controller-uid=4f7ec4f4-c6d0-4299-a800-3bd5d73dc803,job-name=ctlog-createtree-job-pgsqt"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=rekor-search-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-ui,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=segment-backup-installation,app.kubernetes.io/instance-namespace=tsf-tas,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=segment-backup-nightly-metrics,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":6,"labels":"app.kubernetes.io/component=trillian-db,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-db,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=fulcio,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=fulcio-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7fcb76ff7d"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,batch.kubernetes.io/job-name=segment-backup-installation-v2zqn,controller-uid=dffaba4e-a137-471a-a75a-1a5417ff0696,job-name=segment-backup-installation-v2zqn"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=ctlog,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-backfill,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"batch.kubernetes.io/controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,batch.kubernetes.io/job-name=rekor-createtree-job-cr87n,controller-uid=70b0d5ef-2c63-4a71-824a-0f3ccb3c0855,job-name=rekor-createtree-job-cr87n"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-ui,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-search-ui,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7c8984c956"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logserver,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logserver,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=c498d5b4c"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=trillian-logsigner,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=trillian-logsigner,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=7b47744ccd"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=cb994f8cc"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":4,"labels":"app.kubernetes.io/component=createtree,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=ctlog,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=6958598444"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-server,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=76df867ff4"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":2,"labels":"app.kubernetes.io/component=tuf,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=tuf-repository-init,app.kubernetes.io/part-of=trusted-artifact-signer,batch.kubernetes.io/controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,batch.kubernetes.io/job-name=tuf-repository-init-hpwgw,controller-uid=db8010b8-6ab1-4c29-a3ed-d0e37e9690e2,job-name=tuf-repository-init-hpwgw,rhtas.redhat.com/resource=tuf"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":5,"labels":"app.kubernetes.io/component=rekor-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=rekor-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tas","items":1,"labels":"app.kubernetes.io/component=backfill-redis,app.kubernetes.io/instance=trusted-artifact-signer,app.kubernetes.io/managed-by=controller-manager,app.kubernetes.io/name=backfill-redis,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tas"} {"level":"info","ts":"2026-05-07T12:04:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":4,"labels":"name=cert-manager-operator,pod-template-hash=7846db775"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager-metrics-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=cert-manager-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"app.kubernetes.io/component=manager,app.kubernetes.io/created-by=cert-manager-operator,app.kubernetes.io/instance=controller-manager,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=deployment,app.kubernetes.io/part-of=cert-manager-operator,olm.deployment-spec-hash=bbjbJFNGFDrY9hLcTLtsRqMxIUyeAjrXumiGwa,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=cert-manager-operator,olm.owner=cert-manager-operator.v1.19.0,olm.permissions.hash=5BvcE6aNRl1kjQ4qoZiC75uAhCACnLI6hzXqiT,operators.coreos.com/openshift-cert-manager-operator.cert-manager-operator="} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager-operator"} {"level":"info","ts":"2026-05-07T12:04:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":5,"labels":"control-plane=controller-manager,pod-template-hash=84ff8464cd"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,control-plane=controller-manager,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=image-controller,konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"image-controller","items":2,"labels":"konflux.konflux-ci.dev/component=image-controller,konflux.konflux-ci.dev/owner=konflux-image-controller"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"image-controller"} {"level":"info","ts":"2026-05-07T12:04:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":5,"labels":"control-plane=controller-manager,pod-template-hash=5bd6679b5d"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,control-plane=controller-manager,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=build-service,konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"build-service","items":2,"labels":"konflux.konflux-ci.dev/component=build-service,konflux.konflux-ci.dev/owner=konflux-build-service"} {"level":"debug","ts":"2026-05-07T12:04:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"build-service"} {"level":"info","ts":"2026-05-07T12:04:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:04:38.359638 1 request.go:752] "Waited before sending request" delay="1.379691125s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/enterprise-contract-service/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NTIwNzcsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T12:04:40Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"enterprise-contract-service","items":2,"labels":"konflux.konflux-ci.dev/component=enterprise-contract,konflux.konflux-ci.dev/owner=konflux-enterprise-contract"} {"level":"debug","ts":"2026-05-07T12:04:40Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"enterprise-contract-service"} {"level":"info","ts":"2026-05-07T12:04:40Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:04:44Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-cli","items":2,"labels":"konflux.konflux-ci.dev/component=cli,konflux.konflux-ci.dev/owner=konflux-cli"} {"level":"debug","ts":"2026-05-07T12:04:44Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-cli"} {"level":"info","ts":"2026-05-07T12:04:44Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:04:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":2,"labels":"app.kubernetes.io/name=segment-bridge,konflux.konflux-ci.dev/component=segment-bridge,konflux.konflux-ci.dev/owner=konflux-segment-bridge"} {"level":"debug","ts":"2026-05-07T12:04:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"debug","ts":"2026-05-07T12:04:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"segment-bridge","items":3,"labels":"batch.kubernetes.io/controller-uid=082ba1e8-7a00-4975-bb43-436004f58eb9,batch.kubernetes.io/job-name=segment-bridge-29635920,controller-uid=082ba1e8-7a00-4975-bb43-436004f58eb9,job-name=segment-bridge-29635920"} {"level":"debug","ts":"2026-05-07T12:04:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"segment-bridge"} {"level":"info","ts":"2026-05-07T12:04:46Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:04:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":2,"labels":"batch.kubernetes.io/controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,batch.kubernetes.io/job-name=tsf-tekton-configuration,controller-uid=22e394c0-8d73-4f3a-abb5-8de482b1d3fb,job-name=tsf-tekton-configuration"} {"level":"debug","ts":"2026-05-07T12:04:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"debug","ts":"2026-05-07T12:04:48Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf","items":1,"labels":"app.kubernetes.io/instance=tsf-pipelines,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=tsf-pipelines,app.kubernetes.io/version=1.20,helm.sh/chart=tsf-pipelines-0.1.0"} {"level":"debug","ts":"2026-05-07T12:04:48Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf"} {"level":"info","ts":"2026-05-07T12:04:48Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:04:50.360308 1 request.go:752] "Waited before sending request" delay="1.918360632s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/rhbk-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NTIyMTAsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T12:04:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.deployment-spec-hash=OjaPuHGGxLFCnrJjtfw2cSJ0s4Yycb6L920Ue,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T12:04:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:04:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T12:04:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:04:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:04:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:04:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=rhbk-operator,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T12:04:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:04:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":4,"labels":"name=rhbk-operator,pod-template-hash=566fd969fb"} {"level":"debug","ts":"2026-05-07T12:04:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"debug","ts":"2026-05-07T12:04:52Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"rhbk-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/rhbk-operator.rhbk-operator="} {"level":"debug","ts":"2026-05-07T12:04:52Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"rhbk-operator"} {"level":"info","ts":"2026-05-07T12:04:52Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":2,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak-realm-import,batch.kubernetes.io/controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,batch.kubernetes.io/job-name=tsf-iam,controller-uid=4e126cf0-0a6b-4e5e-8b88-5e031256b437,job-name=tsf-iam"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":8,"labels":"app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"app.kubernetes.io/instance=tsf-iam,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=4O0tiObYrrFrlUWdzQmHj2sVWezFneLyYDCeOp"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":1,"labels":"olm.copiedFrom=rhbk-operator,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-keycloak,olm.owner=rhbk-operator.v26.4.11-opr.2,olm.permissions.hash=36jW9QlaNsvzPJGRuCuNRcHk7hOZa26E3ofORt"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":4,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":6,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=keycloak,app.kubernetes.io/managed-by=keycloak-operator,app=keycloak,apps.kubernetes.io/pod-index=0,controller-revision-hash=keycloak-d9447648f,statefulset.kubernetes.io/pod-name=keycloak-0"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-keycloak","items":5,"labels":"app=keycloak-pgsql-bee,phase=reference,pod-template-hash=9c8768f87"} {"level":"debug","ts":"2026-05-07T12:04:56Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-keycloak"} {"level":"info","ts":"2026-05-07T12:04:56Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:04:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":7,"labels":"apps=namespace-lister,pod-template-hash=64f6bbdbd7"} {"level":"debug","ts":"2026-05-07T12:04:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T12:04:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T12:04:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"debug","ts":"2026-05-07T12:04:58Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"namespace-lister","items":4,"labels":"apps=namespace-lister,konflux.konflux-ci.dev/component=namespace-lister,konflux.konflux-ci.dev/owner=konflux-namespace-lister"} {"level":"debug","ts":"2026-05-07T12:04:58Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"namespace-lister"} {"level":"info","ts":"2026-05-07T12:04:58Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:05:02.360059 1 request.go:752] "Waited before sending request" delay="1.996276845s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-ui/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NTIzMzMsInN0YXJ0Ijoic3lzdGVtOmltYWdlLWJ1aWxkZXJzXHUwMDAwIn0&limit=5" {"level":"debug","ts":"2026-05-07T12:05:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=proxy,pod-template-hash=f5494b477"} {"level":"debug","ts":"2026-05-07T12:05:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:05:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T12:05:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:05:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":4,"labels":"app=proxy,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T12:05:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:05:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":3,"labels":"app=dex,konflux.konflux-ci.dev/component=ui,konflux.konflux-ci.dev/owner=konflux-ui"} {"level":"debug","ts":"2026-05-07T12:05:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:05:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":2,"labels":"app=proxy,pod-template-hash=576d699968"} {"level":"debug","ts":"2026-05-07T12:05:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"debug","ts":"2026-05-07T12:05:02Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-ui","items":5,"labels":"app=dex,pod-template-hash=c45c66657"} {"level":"debug","ts":"2026-05-07T12:05:02Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-ui"} {"level":"info","ts":"2026-05-07T12:05:02Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,build.appstudio.redhat.com/build_type=docker,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=build-container,tekton.dev/task=buildah-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-build-container,tekton.dev/taskRunUID=928d1716-52f1-4086-acde-b0922fdcdc8e"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=clamav-scan,tekton.dev/task=clamav-scan-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-clamav-scan,tekton.dev/taskRunUID=6e217671-97ee-49a7-b4a5-20db596ee2a8"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=deprecated-base-image-check,tekton.dev/task=deprecated-image-check,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-deprecated-base-image-check,tekton.dev/taskRunUID=25290786-aa32-4203-8224-1c9ea10427b8"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=rpms-signature-scan,tekton.dev/task=rpms-signature-scan,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-rpms-signature-scan,tekton.dev/taskRunUID=0418ba0d-bdbf-46af-89ba-76ff6cd964a4"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=sast-unicode-check,tekton.dev/task=sast-unicode-check-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-sast-unicode-check,tekton.dev/taskRunUID=a4452541-12ac-48da-81e4-8750b861b55f"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":3,"labels":"konflux.konflux-ci.dev/component=default-tenant,konflux.konflux-ci.dev/owner=konflux-default-tenant"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,build.appstudio.redhat.com/build_type=docker,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=build-image-index,tekton.dev/task=build-image-index-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-build-image-index,tekton.dev/taskRunUID=7e90f568-f3f3-4490-8adf-e23c7d2efe51"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=clone-repository,tekton.dev/task=git-clone-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-clone-repository,tekton.dev/taskRunUID=1c0f8bc5-dfdb-4e1d-a0ab-87a817e79d26"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=init,tekton.dev/task=init,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-init,tekton.dev/taskRunUID=1bd32f43-9e28-4f54-bee7-ea3a658fce0d"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=prefetch-dependencies,tekton.dev/task=prefetch-dependencies-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-prefetch-dependencies,tekton.dev/taskRunUID=86fa5261-1324-4c31-90a0-26e8ba9e9d71"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=sast-shell-check,tekton.dev/task=sast-shell-check-oci-ta-min,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-sast-shell-check,tekton.dev/taskRunUID=aa2230fa-34b9-4f08-b680-410c1ccdaa32"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"default-tenant","items":1,"labels":"app.kubernetes.io/managed-by=tekton-pipelines,app.kubernetes.io/version=v0.37.7,appstudio.openshift.io/application=tsf-app,appstudio.openshift.io/component=tsf-comp-6vc6m,pipelines.appstudio.openshift.io/type=build,pipelinesascode.tekton.dev/cancel-in-progress=false,pipelinesascode.tekton.dev/check-run-id=74809009768,pipelinesascode.tekton.dev/event-type=push,pipelinesascode.tekton.dev/original-prname=tsf-comp-6vc6m-on-push,pipelinesascode.tekton.dev/repository=tsf-comp-6vc6m,pipelinesascode.tekton.dev/sha=0b6ee4b81cc30389567b5cb9d9572a67b0d39657,pipelinesascode.tekton.dev/state=started,pipelinesascode.tekton.dev/url-org=rhads-tsf-qe,pipelinesascode.tekton.dev/url-repository=testrepo,tekton.dev/memberOf=tasks,tekton.dev/pipeline=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRun=tsf-comp-6vc6m-on-push-gmhmp,tekton.dev/pipelineRunUID=345ba199-dc2e-428c-b571-fc160fa03c19,tekton.dev/pipelineTask=tpa-scan,tekton.dev/task=tpa-scan,tekton.dev/taskRun=tsf-comp-6vc6m-on-push-gmhmp-tpa-scan,tekton.dev/taskRunUID=eb3e9019-9599-4aa3-97d2-7d2ffc08261d"} {"level":"debug","ts":"2026-05-07T12:05:06Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"default-tenant"} {"level":"info","ts":"2026-05-07T12:05:06Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:05:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T12:05:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:05:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":2,"labels":"control-plane=controller-manager,pod-template-hash=867646c8cc"} {"level":"debug","ts":"2026-05-07T12:05:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:05:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=5c659bbf77"} {"level":"debug","ts":"2026-05-07T12:05:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:05:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":3,"labels":"batch.kubernetes.io/controller-uid=1e06b07d-ee22-4933-a8d2-c911a00ddffd,batch.kubernetes.io/job-name=integration-service-snapshot-garbage-collector-29635920,controller-uid=1e06b07d-ee22-4933-a8d2-c911a00ddffd,job-name=integration-service-snapshot-garbage-collector-29635920"} {"level":"debug","ts":"2026-05-07T12:05:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:05:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":5,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T12:05:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"debug","ts":"2026-05-07T12:05:10Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"integration-service","items":1,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/created-by=integration-service,app.kubernetes.io/instance=webhook-service,app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=service,app.kubernetes.io/part-of=integration-service,konflux.konflux-ci.dev/component=integration,konflux.konflux-ci.dev/owner=konflux-integration-service"} {"level":"debug","ts":"2026-05-07T12:05:10Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"integration-service"} {"level":"info","ts":"2026-05-07T12:05:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T12:05:10Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:05:12.360386 1 request.go:752] "Waited before sending request" delay="1.821879573s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/konflux-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NTI0NjksInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:05:14Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T12:05:14Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:05:18Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T12:05:18Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T12:05:18Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:05:22Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T12:05:22Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:05:24.359033 1 request.go:752] "Waited before sending request" delay="1.915235834s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NTI2MDUsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtYWxlcnQtcm91dGluZy1lZGl0LTBcdTAwMDAifQ&limit=5" {"level":"debug","ts":"2026-05-07T12:05:24Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T12:05:24Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T12:05:24Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T12:05:26Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:05:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T12:05:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:05:28Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:05:28Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T12:05:28Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:05:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T12:05:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:05:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T12:05:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:05:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T12:05:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:05:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T12:05:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:05:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T12:05:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:05:32Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T12:05:32Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T12:05:32Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:05:34.359955 1 request.go:752] "Waited before sending request" delay="1.921978332s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/rhtpa-operator/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NTI3MTUsInN0YXJ0IjoiL2RlZGljYXRlZC1hZG1pbnMtMVx1MDAwMCJ9&limit=5" {"level":"info","ts":"2026-05-07T12:05:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has ended"} {"level":"info","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciliation loop has started"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":1,"Group":"batch","Version":"v1","Kind":"Job"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":2,"Group":"policy","Version":"v1","Kind":"PodDisruptionBudget"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":3,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRoleBinding"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":4,"Group":"apps","Version":"v1","Kind":"DaemonSet"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":5,"Group":"","Version":"v1","Kind":"PersistentVolumeClaim"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":6,"Group":"","Version":"v1","Kind":"ServiceAccount"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":7,"Group":"apps.openshift.io","Version":"v1","Kind":"DeploymentConfig"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":8,"Group":"networking.k8s.io","Version":"v1","Kind":"Ingress"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":9,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"RoleBinding"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":10,"Group":"apps","Version":"v1","Kind":"ReplicaSet"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":11,"Group":"","Version":"v1","Kind":"Service"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":12,"Group":"autoscaling","Version":"v1","Kind":"HorizontalPodAutoscaler"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":13,"Group":"batch","Version":"v1","Kind":"CronJob"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":14,"Group":"networking.k8s.io","Version":"v1","Kind":"NetworkPolicy"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":15,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"ClusterRole"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":16,"Group":"rbac.authorization.k8s.io","Version":"v1","Kind":"Role"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":17,"Group":"","Version":"v1","Kind":"Pod"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":18,"Group":"","Version":"v1","Kind":"ReplicationController"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":19,"Group":"apps","Version":"v1","Kind":"Deployment"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"apiResource","no":20,"Group":"apps","Version":"v1","Kind":"StatefulSet"} {"level":"info","ts":"2026-05-07T12:06:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":5,"labels":"app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,pod-template-hash=5fb678d5f4"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=konflux-operator,control-plane=controller-manager,olm.deployment-spec-hash=a6IgdKnq2dyzWxzss4ouu5494lYw9l4nKHaLrO,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":2,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=jFynzryran0Td5CUgJ3rwrkK6ZdYd35f5iILp,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-operator","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=konflux-operator,olm.owner=konflux-operator.v0.1.12,olm.permissions.hash=6VkYjWmwqEjnVGzheji50fOML3rUm81RARgZTo,operators.coreos.com/konflux-operator.konflux-operator="} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-operator"} {"level":"info","ts":"2026-05-07T12:06:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"konflux-info","items":2,"labels":"konflux.konflux-ci.dev/component=info,konflux.konflux-ci.dev/owner=konflux-info"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"konflux-info"} {"level":"info","ts":"2026-05-07T12:06:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=storage,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=server,pod-template-hash=5ddf8d448b"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"server","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=importer,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"dnsconfig-options","check_description":"Alert on deployments that have no specified dnsConfig options","check_remediation":"Specify dnsconfig options in your Pod specification to ensure the expected DNS setting on the Pod. Refer to https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config for details.","check_failure_reason":"Object does not define any DNSConfig rules."} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"env-value-from","check_description":"Indicates when objects use a secret or configmap not included in the deployment.","check_remediation":"Change the name or key to match a secret / configmap in the deployment.","check_failure_reason":"The container \"service\" is referring to an unknown secret \"tpa-pgsql-user\""} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"minimum-three-replicas","check_description":"Indicates when a deployment uses less than three replicas","check_remediation":"Increase the number of replicas in the deployment to at least three to increase the fault tolerance of the deployment.","check_failure_reason":"object has 1 replica but minimum required replicas is 3"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"no-node-affinity","check_description":"Alert on deployments that have no node affinity defined","check_remediation":"Specify node-affinity in your pod specification to ensure that the orchestrator attempts to schedule replicas on specified nodes. Refer to https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity for details.","check_failure_reason":"object does not define any node affinity rules."} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"non-isolated-pod","check_description":"Alert on deployment-like objects that are not selected by any NetworkPolicy.","check_remediation":"Ensure pod does not accept unsafe traffic by isolating it with a NetworkPolicy. See https://cloud.redhat.com/blog/guide-to-kubernetes-ingress-network-policies for more details.","check_failure_reason":"pods created by this object are non-isolated"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"run-as-non-root","check_description":"Indicates when containers are not set to runAsNonRoot.","check_remediation":"Set runAsUser to a non-zero number and runAsNonRoot to true in your pod or container securityContext. Refer to https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ for details.","check_failure_reason":"container \"service\" is not set to runAsNonRoot"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"validationEngine","msg":"New Metric has been created","namespace":"tsf-tpa","object":"importer","kind":"Deployment","validation":"unset-memory-requirements","check_description":"Indicates when containers do not have memory requests and limits set.","check_remediation":"Set memory limits for your container based on its requirements. Refer to https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#requests-and-limits for details.","check_failure_reason":"container \"service\" has memory limit 0"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"control-plane=controller-manager,pod-template-hash=7fb98566b7"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app.kubernetes.io/component=server,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/managed-by=Helm,app.kubernetes.io/name=server,app.kubernetes.io/part-of=trustify,app.kubernetes.io/version=2.2.4"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"olm.managed=true"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"type=importer-working-directory"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":4,"labels":"app.kubernetes.io/component=importer,app.kubernetes.io/instance=trustedprofileanalyzer,app.kubernetes.io/name=importer,pod-template-hash=6f455fcc59"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":5,"labels":"app=tpa-pgsql-bee,phase=reference,pod-template-hash=5f9d857cf7"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":2,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=rhtpa-operator,control-plane=controller-manager,olm.deployment-spec-hash=8fucnhxszcx4HqECFIyBsVK4GAHrIAx4puAdjk,olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":3,"labels":"app.kubernetes.io/managed-by=Helm"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=89zmJTEa8x4dF5PYcd2jJAXBQdRMGCux5nsqKM,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"tsf-tpa","items":1,"labels":"olm.managed=true,olm.owner.kind=ClusterServiceVersion,olm.owner.namespace=tsf-tpa,olm.owner=rhtpa-operator.v1.1.4,olm.permissions.hash=aFImzaN7XMTLc0qsAWHiSsv2PNOJPMjP0l04oA,operators.coreos.com/rhtpa-operator.tsf-tpa="} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"tsf-tpa"} {"level":"info","ts":"2026-05-07T12:06:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4","items":2,"labels":"open-cluster-management.io/created-by-klusterlet=klusterlet-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"open-cluster-management-2q527bvkh7gr4u97845sc0tcktnqd3u4"} {"level":"info","ts":"2026-05-07T12:06:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T12:06:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer,pod-template-hash=69447b45bd"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"trusted-artifact-signer","items":5,"labels":"app.kubernetes.io/component=client-server,app.kubernetes.io/part-of=trusted-artifact-signer"} {"level":"debug","ts":"2026-05-07T12:06:36Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"trusted-artifact-signer"} {"level":"info","ts":"2026-05-07T12:06:36Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} I0507 12:06:38.360366 1 request.go:752] "Waited before sending request" delay="1.370772692s" reason="client-side throttling, not priority and fairness" verb="GET" URL="https://172.30.0.1:443/apis/rbac.authorization.k8s.io/v1/namespaces/cert-manager/rolebindings?continue=eyJ2IjoibWV0YS5rOHMuaW8vdjEiLCJydiI6NTM0NjUsInN0YXJ0Ijoic3lzdGVtOmRlcGxveWVyc1x1MDAwMCJ9&limit=5" {"level":"debug","ts":"2026-05-07T12:06:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager"} {"level":"debug","ts":"2026-05-07T12:06:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:06:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector"} {"level":"debug","ts":"2026-05-07T12:06:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:06:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":7,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook"} {"level":"debug","ts":"2026-05-07T12:06:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:06:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=controller,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cert-manager,app.kubernetes.io/version=v1.19.4,app=cert-manager,pod-template-hash=79c8d999ff"} {"level":"debug","ts":"2026-05-07T12:06:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:06:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=cainjector,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=cainjector,app.kubernetes.io/version=v1.19.4,app=cainjector,pod-template-hash=68b757865b"} {"level":"debug","ts":"2026-05-07T12:06:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"debug","ts":"2026-05-07T12:06:38Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"cert-manager","items":5,"labels":"app.kubernetes.io/component=webhook,app.kubernetes.io/instance=cert-manager,app.kubernetes.io/name=webhook,app.kubernetes.io/version=v1.19.4,app=webhook,pod-template-hash=587ccfb98"} {"level":"debug","ts":"2026-05-07T12:06:38Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"cert-manager"} {"level":"info","ts":"2026-05-07T12:06:38Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"info","ts":"2026-05-07T12:06:43Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"} {"level":"debug","ts":"2026-05-07T12:06:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":6,"labels":"control-plane=controller-manager,pod-template-hash=544796b49f"} {"level":"debug","ts":"2026-05-07T12:06:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T12:06:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":4,"labels":"app.kubernetes.io/managed-by=kustomize,app.kubernetes.io/name=test,control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T12:06:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T12:06:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":5,"labels":"konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T12:06:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"debug","ts":"2026-05-07T12:06:46Z","logger":"GenericReconciler","msg":"Reconciling Namespace Resources","ns":"release-service","items":2,"labels":"control-plane=controller-manager,konflux.konflux-ci.dev/component=release,konflux.konflux-ci.dev/owner=konflux-release-service"} {"level":"debug","ts":"2026-05-07T12:06:46Z","logger":"GenericReconciler","msg":"All objects are validated, ending loop","ns":"release-service"} {"level":"info","ts":"2026-05-07T12:06:47Z","msg":"apps.openshift.io/v1 DeploymentConfig is deprecated in v4.14+, unavailable in v4.10000+"}